Reproducing, disclosing, and fixing the libheif vulnerability with Hacktron and the maintainers Hacktron reported a remote code execution vulnerability in August 2026 that traced to libheif, an AVIF image decoder used by Next.js, ImageMagick, WordPress, and sharp, rather than to Next.js itself. Vercel applied a platform-wide mitigation through its Image Optimization Service on August 13, and the libheif maintainer released v1.23.2 on August 25 to remediate the RCE, the same day Next.js published a security release that disabled AVIF optimization. The disclosure was coordinated across sharp, libvips, and libheif after Hacktron and Vercel reproduced the exploit with a working proof of concept on August 11-12. In August 2026, Hacktron https://www.hacktron.ai/ reported what looked like a remote code execution RCE vulnerability in Next.js image optimization. Their investigation found that the vulnerable code was not in Next.js itself, but upstream in libheif, an AVIF image decoder used by Next.js, ImageMagick https://github.com/strukturag/libheif software-using-libheif , WordPress https://make.wordpress.org/core/2024/08/15/automatic-conversion-of-heic-images-to-jpeg-in-wordpress-6-7/ , sharp https://github.com/strukturag/libheif software-using-libheif , and much of the web. Shortly after Hacktron notified us, we worked with them to reproduce the RCE against a current Next.js build and disclose it to the maintainers of sharp, libvips, and libheif. We then deployed a platform-wide mitigation on Vercel and started working with the maintainers on a fix. Next.js image optimization lets applications resize and optimize images through the