-
-
Notifications
You must be signed in to change notification settings - Fork 192
Open
Description
While working on sonicjs project, I discovered a vulnerability in the @opennextjs/cloudflare package (CVE-2026-3125). The issue is caused by a path normalization bypass in the /cdn-cgi/image handler. By using a backslash () instead of a forward slash (/) in the request path, an attacker can bypass Cloudflare edge interception and make the Worker fetch arbitrary remote URLs.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels