CVE-2026-3125 | opennextjs cloudflare up to 1.17.0 /cdn-cgi/image/ server-side request forgery (GHSA-rvpw-p7vw-wj3m)
A vulnerability was found in opennextjs cloudflare up to 1.17.0. It has been declared as critical. This issue affects some unknown processing of the file /cdn-cgi/image/. The manipulation results in server-side request forgery.
This vulnerability was named CVE-2026-3125. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.