OpenNextjs maintains a focused deployment adapter that bridges Next.js applications to Cloudflare's edge-computing platform, representing a narrow but strategically positioned integration point in serverless and edge architectures. The observed vulnerability pattern centers on server-side request forgery and name-resolution issues, reflecting the complexity of proxying and URL handling in a cross-platform request adapter. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opennextjs over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-6087CRITICAL A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package. The vulnerability stems from an unimplemented feature in the Cloudflare ada | Jun 16, 2025 | 9.1 | 27 | NO | NO |
CVE-2026-3125MEDIUM A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package, resulting from a path normalization bypass in the /cdn-cgi/image/ handler.T | Mar 4, 2026 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opennextjs.
Media articles that mention a CVE ID that affects a product developed by Opennextjs — matched by CVE ID, not by vendor name.