AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Next/Image Optimizer Ignores HTTP(S)_PROXY In Next.Js 16.3.8

Starting with 16.3.8, the Next.js image optimization server fetches remote images using ImageHttpAgent/ImageHttpsAgent without proxyEnv, causing direct connections that ignore HTTP_PROXY/HTTPS_PROXY and global undici dispatchers. In proxied environments, all remote image requests time out with 504.

highConfidence 90%Next.jsAffected V16.3.8

Origin Analysis

The security release 16.3.8 switched the image optimizer from fetch(href) to ImageHttpAgent/ImageHttpsAgent with pinned DNS lookup. These agents are created with only { keepAlive: true, timeout: 7000 }, so they do not inherit proxy configuration from process.env (HTTP_PROXY/HTTPS_PROXY) nor from a global undici dispatcher, unlike the rest of the server.
1. Clone https://github.com/gergokee/next-image-proxy-repro 2. Run npm install && npm run build 3. Start a logging forward proxy on :8888 (npm run proxy) 4. Start the app with HTTPS_PROXY=http://localhost:8888 HTTP_PROXY=http://localhost:8888 NO_PROXY=localhost,127.0.0.1 NODE_USE_ENV_PROXY=1 npm start 5. Run npm run check, which triggers a route handler fetch() and a /_next/image request for a remote image 6. Observe proxy logs: fetch() goes through proxy, but the image optimizer does not, resulting in 504

Fixing Code Block

Edge Case Audit

proxyEnv is only recognized by Node.js v24.5.0+ and v22.21.0+; on older Node versions the fix silently has no effect. Additionally, with a proxy the remote hostname is resolved by the proxy, so the pinned DNS SSRF protection only validates the local DNS answer; an attacker who controls the proxy could redirect requests. Consider making this behavior opt-in via an images config option or only activating when HTTP(S)_PROXY is explicitly set. Rollback is safe by removing the added condition.

Ecosystem Topology