Critical
Reading the Next.js ImageResponse advisory
CVE-2026-94545 is a Satori escaping bug that Vercel says can become code execution in Node.js next/og. The only published numeric score is 5.3. Next.js 16.3.6 is the fix. A public PoC exists.
Published 3h ago
Critical
The Gotenberg public PoC is not a confirmed RCE
CVE-2026-40281 has a public repository and a CVSS 10.0 score. The vendor advisory describes unauthenticated file move, overwrite, and link creation inside the container. Code execution is not the published impact.
Published 3h ago
CriticalPoC Available
Satori SVG injection affecting Next.js ImageResponse
RCE
Published 6d ago
CriticalPoC Available
Gotenberg ExifTool argument injection
Other
Published 6 May 2026