GCP-2026-055

Imported from official source

Security notice

Cybersecurity Classified by Officially

Published: 2026-08-25

Description

Description Severity Notes

A critical unauthenticated Remote Code Execution (RCE) vulnerability exists in Next.js and libheif when processing malicious image files. Google Cloud infrastructure is not directly vulnerable, but customer workloads running Next.js on Google Cloud (e.g., Cloud Run, GKE, App Engine) may be affected.

What should I do?

Google Cloud backend services are not directly impacted, and no action is required to secure the underlying Google Cloud infrastructure. However, customers hosting Next.js applications on Google Cloud must take immediate action to secure their own workloads. We recommend that you manually upgrade your Next.js deployments to one of the following versions (or later) in your package.json: 

  • 16.3.3
  • 15.5.24
Customers utilizing libheif should monitor for upstream OS patches and rebuild their container base images accordingly. Redeploy your updated workloads to ensure running containers utilize the patched versions.

What vulnerabilities are being addressed?

The vulnerabilities, GHSA-2xp9-vwfh-vxw4 and GHSA-g89c-p67h-r497, allow an attacker to execute arbitrary code within the context of the application by supplying a crafted image file during Next.js image optimization. This issue occurs due to how the underlying libheif library processes clean aperture boxes in HEIF/AVIF images.

High GHSA-2xp9-vwfh-vxw4

This is an extract. The publication continues at the source.

Read the original at the source: https://docs.cloud.google.com/support/bulletins/index#gcp-2026-055

Officially imported this from Google’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

This publication has changed since it was first published

4 versions recorded. The original is kept in full — nothing is overwritten.

  1. v4 imported change on current
  2. v3 imported change on
  3. v2 imported change on
  4. v1 as first published on

Provenance

Organization
Google — imported from official source
Official source
https://cloud.google.com/feeds/google-cloud-security-bulletins.xml RSS
Imported
September 15, 2026 20:57
Versions
4 recorded
Identity
tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-055

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.