Skip to content

Commit c87e792

Browse files
Update src/content/changelog/workers/2025-06-17-open-next-ssrf.mdx
Co-authored-by: Brendan Irvine-Broque <[email protected]>
1 parent c49afbb commit c87e792

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

src/content/changelog/workers/2025-06-17-open-next-ssrf.mdx

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ products:
66
date: 2025-06-17T01:00:00Z
77
---
88

9-
A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package, which has been automatically mitigated for all existing deployments.
9+
A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package, which has been automatically mitigated for all Next.js apps deployed to Cloudflare that use the @opennextjs/cloudflare package.
1010

1111
The vulnerability stems from an unimplemented feature in the Cloudflare adapter for Open Next, which allowed users to proxy arbitrary remote content via the `/_next/image` endpoint.
1212

0 commit comments

Comments
 (0)