CVE-2026-3125Disclosure(opennextjs / opennext_for_cloudflare)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package, resulting from a path normalization bypass in the /cdn-cgi/image/ handler.The @opennextjs/cloudflare worker template includes a /cdn-cgi/image/ handler intended for development use only. In production, Cloudflare's edge intercepts /cdn-cgi/image/ requests before they reach the Worker. However, by substituting a backslash for a forward slash (/cdn-cgi\image/ instead of /cdn-cgi/image/), an attacker can bypass edge interception and have the request reach the Worker directly. The JavaScript URL class then normalizes the backslash to a forward slash, causing the request to match the handler and trigger an unvalidated fetch of arbitrary remote URLs. For example: https://victim-site.com/cdn-cgi\image/aaaa/https://attacker.com In this example, attacker-controlled content from attacker.com is served through the victim site's domain (victim-site.com), violating the same-origin policy and potentially misleading users or other services. Note: This bypass only works via HTTP clients that preserve backslashes in paths (e.g., curl --path-as-is). Browsers normalize backslashes to forward slashes before sending requests. Additionally, Cloudflare Workers with Assets and Cloudflare Pages suffer from a similar vulnerability. Assets stored under /cdn-cgi/ paths are not publicly accessible under normal conditions. However, using the same backslash bypass (/cdn-cgi\... instead of /cdn-cgi/...), these assets become publicly accessible. This could be used to retrieve private data. For example, Open Next projects store incremental cache data under /cdn-cgi/_next_cache, which could be exposed via this bypass.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-706CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opennext_for_cloudflare

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-05)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
opennext_for_cloudflare

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-04: 1Mentions · 2026-03-05: 2Technical Details · 2026-03-04: 1Technical Details · 2026-03-05: 103-0403-05
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-041
Disclosure1
2026-03-052
Disclosure2
Full discourse3 posts
  • ezzer@ez_z3r
    Disclosure

    Got a new high CVE-2026-3125 in the opennextjs-cloudflare. More then 30k web properties were vulnerable in censys last time I checked https://github.com/opennextjs/opennextjs-cloudflare/security/advisories/GHSA-c7mq-gh6q-6q7c

    Post summary

    A new high‑severity CVE-2026-3125 affecting opennextjs‑cloudflare has been identified, with over 30,000 vulnerable web properties reported; a GitHub security advisory is linked.

    0001199
    76 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3125 Server-Side Request Forgery in @opennextjs/cloudflare via Path Normalization Bypass https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3125

    Post summary

    The post announces a Server‑Side Request Forgery vulnerability (CVE‑2026‑3125) in @opennextjs/cloudflare, detailing a path normalization bypass, but provides no proof‑of‑concept, exploit, or patch information.

    0000067
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3125 A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package, resulting from a path normalization bypass in the /cdn-cgi/imag… https://www.cve.org/CVERecord?id=CVE-2026-3125

    Post summary

    An announcement of a Server‑Side Request Forgery (SSRF) vulnerability (CVE‑2026‑3125) in the @opennextjs/cloudflare package, caused by a path normalization bypass, with no mentions of exploits, patches, or active use.

    00000134
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopennextjsopennext_for_cloudflare-node.js-

Explore more