跳到主内容
精选85Cloudflare WAF(Changelog)云与平台

Cloudflare WAF 紧急更新:新增 Next.js 远程代码执行与 AVIF 图像优化器规则

WAF - WAF Release - 2026-08-26 - Emergency

原文
推荐理由

使用 Cloudflare WAF 的开发者注意:紧急规则已上线,针对 Next.js 两个可被未认证利用的 RCE 漏洞。请尽快确认规则已生效,并安排升级 Next.js 至 16.3.3 或 15.5.24。

This emergency release updates an existing Next.js remote code execution rule to identify CVE-2026-75604 and adds a new rule for remote code execution in the Next.js Image Optimizer via crafted AVIF images.

此紧急发布更新了现有的 Next.js 远程代码执行规则,以识别 CVE-2026-75604,并新增了一条规则,用于检测通过精心构造的 AVIF 图像在 Next.js Image Optimizer 中进行的远程代码执行。

Key Findings

主要发现

  • CVE-2026-75604 affects Windows-hosted Next.js applications using both the Pages Router and App Router without Cache Components and can lead to unauthenticated remote code execution.
  • GHSA-2xp9-vwfh-vxw4 affects the Next.js Image Optimizer and can lead to unauthenticated remote code execution when it optimizes an attacker-controlled AVIF image.
  • CVE-2026-75604 影响在 Windows 上托管的 Next.js 应用程序,这些应用程序同时使用 Pages Router 和 App Router,且未使用 Cache Components,可能导致未经认证的远程代码执行。
  • GHSA-2xp9-vwfh-vxw4 影响 Next.js Image Optimizer,当它优化攻击者控制的 AVIF 图像时,可能导致未经认证的远程代码执行。

Impact

影响

Next.js recommends updating to version 16.3.3 or 15.5.24 to address these vulnerabilities.

Next.js 建议升级到版本 16.3.3 或 15.5.24 以解决这些漏洞。

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed Ruleset...2ca6cce3N/ANext.js - Remote Code Execution - CVE:CVE-2026-75604BlockN/ARule metadata description refined. Detection unchanged.
Cloudflare Managed Ruleset...80256efeN/ANext.js - Image Optimizer Remote Code Execution via Crafted AVIFN/ABlockThis is a new detection.
规则集规则 ID旧规则 ID描述先前操作新操作备注
Cloudflare 托管规则集...2ca6cce3不适用Next.js - 远程代码执行 - CVE:CVE-2026-75604阻止不适用规则元数据描述已细化。检测逻辑未变。
Cloudflare 托管规则集...80256efe不适用Next.js - 通过精心构造的 AVIF 进行 Image Optimizer 远程代码执行不适用阻止这是新的检测。

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

相似阅读

另一事件,读法相近