Next.js image SSRF fix: narrow remotePatterns for Sume

Next.js patched an Image Optimization SSRF via allow-listed remote URLs. Allow only media.sume.com for Sume images, and never raw provider hosts.

4 min readSume
All posts

After the Next.js September 2026 security release, keep images.remotePatterns as narrow as possible. For Sume images that means one entry for media.sume.com, and no entries for raw provider hosts. Update to a patched version first: the fix shipped in v16.3.8 and v15.5.27.

Next.js facts are from its security release post (published 2026-09-30), read 2026-09-30. Sume facts are from Media inputs and Webhooks. This is not a full security review of your app.

What did Next.js fix?

CVE-2026-94483, rated High: an attacker-controlled, allow-listed remote URL can lead to Server-Side Request Forgery, for example to private IP ranges, during Image Optimization. The post says that if no images.remotePatterns are configured, your application is not affected. Patched releases are v16.3.8 (Active LTS) and v15.5.27 (Maintenance LTS).

Which host should I allow for Sume output?

Sume mirrors generated outputs into Sume-owned media URLs and says integrations should store the Sume URL, not raw provider URLs. Artifacts in webhook payloads look like https://media.sume.com/artifacts/..., and the Image API docs show https://media.sume.com/img/... for data[].url. A pattern for those two paths:

What to allow for Sume images, from the Next.js post and Sume docs, read 2026-09-30
EntryAllow it?Why
media.sume.com /artifacts/**YesHosted artifact URLs in job results and webhooks
media.sume.com /img/**YesShape shown for data[].url
A raw provider hostNoNot a public API output; keep the allow-list small
A wildcard hostNoWidens what an attacker-controlled URL can reach
// next.config.js
module.exports = {
  images: {
    remotePatterns: [
      { protocol: "https", hostname: "media.sume.com", pathname: "/artifacts/**" },
      { protocol: "https", hostname: "media.sume.com", pathname: "/img/**" },
    ],
  },
};

Should the URL come from user input?

Treat it as untrusted. Take the URL from your own stored job result, not from a request parameter, so the allow-list is a second guard rather than the only one.

Do I need next/image at all?

Not necessarily. If you skip remotePatterns, the post says you are not affected by this issue, and a plain image tag pointing at the Sume URL works. Sume's docs do not state how long those URLs stay valid, so see downloading a generated video from the API to keep a copy.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume