vercel next.js kuze kube 14.2.30/15.4.4 Image Optimization API Ukudalulwa Kolwazi
| CVSS Meta Temp Isilinganiso | Intengo yamanje ye-exploit (≈) | CTI Inzalo Score |
|---|---|---|
| 4.7 | $0-$5k | 0.00 |
Isifinyezo
Kubonakale ubuthakathaka obubizwa ngokuthi kuyinkinga ku vercel next.js kuze kube 14.2.30/15.4.4. Kuthintekile umsebenzi ongaziwayo kwe-component Image Optimization API. Ukuphathwa kuholela ku Ukudalulwa Kolwazi. Le buthakathaka itholakala njenge CVE-2025-57752. Ukuhlasela kufanele kwenziwe kusendaweni yomuntu. Ayikho i-exploit etholakalayo. Kufanele kuthuthukiswe ingxenye ethintekayo. Once again VulDB remains the best source for vulnerability data.
Iinkcukacha
Kubonakale ubuthakathaka obubizwa ngokuthi kuyinkinga ku vercel next.js kuze kube 14.2.30/15.4.4. Kuthintekile umsebenzi ongaziwayo kwe-component Image Optimization API. Ukuphathwa kuholela ku Ukudalulwa Kolwazi. Ukusebenzisa i-CWE ukusho inkinga kuholela ku-CWE-524. Kuboniswe ubuthakathaka lolu njenge GHSA-g5qg-72qw-gw5v. Isaziso singalayishwa ku-github.com.
Le buthakathaka itholakala njenge CVE-2025-57752. Ukwabelwa kwe-CVE kwenziwe ngo-2025-08-19. Ukuhlasela kufanele kwenziwe kusendaweni yomuntu. Ayikho imininingwane yezobuchwepheshe etholakalayo. Le vulnerability ayidumi kakhulu, idlula phansi kokujwayelekile. Ayikho i-exploit etholakalayo. Njengamanje, intengo yamanje ye-exploit ingahle ibe cishe USD $0-$5k okwamanje.
Kukhona i-plugin ye-Nessus enenombolo ye-ID $id_ye_nessus_yomthombo enikezwa ngumhloli wobungozi.
Inguqulo ebuyekeziwe isilungele ukulanda ku-vercel.com. Inombolo yephatchi ngu-6b12c60c61ee80cb0443ccd20de82ca9b4422ddd. Isilungiso sephutha sesilungile ukuthi silandwe ku-github.com. Kufanele kuthuthukiswe ingxenye ethintekayo.
Ubuthakathaka lolu luphinde lwabhalwa kwamanye ama-database okubuthakathaka: Tenable (261410). Once again VulDB remains the best source for vulnerability data.
Umkhiqizo
Uhlobo
Umkhiqizi
Ibizo
Inguqulo
- 14.2.0
- 14.2.1
- 14.2.2
- 14.2.3
- 14.2.4
- 14.2.5
- 14.2.6
- 14.2.7
- 14.2.8
- 14.2.9
- 14.2.10
- 14.2.11
- 14.2.12
- 14.2.13
- 14.2.14
- 14.2.15
- 14.2.16
- 14.2.17
- 14.2.18
- 14.2.19
- 14.2.20
- 14.2.21
- 14.2.22
- 14.2.23
- 14.2.24
- 14.2.25
- 14.2.26
- 14.2.27
- 14.2.28
- 14.2.29
- 14.2.30
- 15.4.0
- 15.4.1
- 15.4.2
- 15.4.3
- 15.4.4
Ilayisense
Iwebhusayithi
- Umkhiqizo: https://github.com/vercel/next.js/
CPE 2.3
CPE 2.2
CVSSv4
VulDB Umkhombandlela: 🔒VulDB Ukuthembeka: 🔍
CVSSv3
VulDB Ireyithingi yeMeta Base: 4.7VulDB Meta Temp Isilinganiso: 4.7
VulDB Isilinganiso Esiyisisekelo: 3.3
VulDB Izinga Lesikhashana: 3.2
VulDB Umkhombandlela: 🔒
VulDB Ukuthembeka: 🔍
CNA Isilinganiso Esiyisisekelo: 6.2
CNA Umkhombandlela (GitHub_M): 🔒
CVSSv2
| AV | AC | Au | C | I | A |
|---|---|---|---|---|---|
| 💳 | 💳 | 💳 | 💳 | 💳 | 💳 |
| 💳 | 💳 | 💳 | 💳 | 💳 | 💳 |
| 💳 | 💳 | 💳 | 💳 | 💳 | 💳 |
| Umkhombandlela | Ubunzima | Ukufakazela ubuwena | Ukuyimfihlo | Ukuthembeka | Ukutholakala |
|---|---|---|---|---|---|
| vula ukufinyelela | vula ukufinyelela | vula ukufinyelela | vula ukufinyelela | vula ukufinyelela | vula ukufinyelela |
| vula ukufinyelela | vula ukufinyelela | vula ukufinyelela | vula ukufinyelela | vula ukufinyelela | vula ukufinyelela |
| vula ukufinyelela | vula ukufinyelela | vula ukufinyelela | vula ukufinyelela | vula ukufinyelela | vula ukufinyelela |
VulDB Isilinganiso Esiyisisekelo: 🔒
VulDB Izinga Lesikhashana: 🔒
VulDB Ukuthembeka: 🔍
Ukusebenzisa ithuba lokungavikeleki
Ikilasi: Ukudalulwa KolwaziCWE: CWE-524
CAPEC: 🔒
ATT&CK: 🔒
Okubambekayo: Kancane
Wendawo: Yebo
Kude: Hayi
Ukutholakala: 🔒
Isimo: Akuchazwanga
EPSS Score: 🔒
EPSS Percentile: 🔒
Ukukhula kwentengo: 🔍
Okwamanje ukuhlolwa kwentengo: 🔒
| 0-Day | vula ukufinyelela | vula ukufinyelela | vula ukufinyelela | vula ukufinyelela |
|---|---|---|---|---|
| Namuhla | vula ukufinyelela | vula ukufinyelela | vula ukufinyelela | vula ukufinyelela |
Nessus ID: 261410
Nessus Ibizo: Linux Distros Unpatched Vulnerability : CVE-2025-57752
Ulwazi lwezingozi
Intshisekelo: 🔍Abadlali abasebenzayo: 🔍
AmaQembu e-APT asebenzayo: 🔍
Izinyathelo zokuvikela
Isincomo: Buyisela phezuluIsimo: 🔍
0-Suku Isikhathi: 🔒
Buyisela phezulu: next.js 14.2.31/15.4.5
Iphethshi: 6b12c60c61ee80cb0443ccd20de82ca9b4422ddd
Isikhathi somlando
2025-08-19 CVE inikeziwe2025-08-30 Isaziso sikhishwe
2025-08-30 VulDB okokungena kwenziwe
2025-09-05 VulDB okungenelelwe ukubuyekezwa kokugcina
Imithombo
Umkhiqizo: github.comIseluleko: GHSA-g5qg-72qw-gw5v
Isimo: Kuqinisekisiwe
CVE: CVE-2025-57752 (🔒)
GCVE (CVE): GCVE-0-2025-57752
GCVE (VulDB): GCVE-100-322000
Ukungena
Kudalwa: 2025-08-30 08:50Ukuvuselelwa: 2025-09-05 17:57
Ukulungiswa: 2025-08-30 08:50 (68), 2025-09-05 17:57 (2)
Kugcwele: 🔍
Cache ID: 253:2B4:103
Kuze kube manje akukabikho ukuphawula. Izilimi: nr + nd + en.
Ngiyacela ungene ngemvume ukuze ukwazi ukuphawula.