Reproducing, disclosing, and fixing the libheif vulnerability with Hacktron and the maintainers
By Steven Van ·
In August 2026, Hacktron reported what looked like a remote code execution (RCE) vulnerability in Next.js image optimization.
I can't write this post as specified: the "full text of the original announcement" provided is not about Vercel, Next.js, or libheif at all. It's a different article entirely — Anil Madhavapeddy's personal blog post about a path-traversal bug he fixed in OCaml's `cohttp`, and a broader essay about AI agents finding exploits faster than maintainers can patch them ("bugonomics"). It never mentions Vercel, Hacktron, Next.js, sharp, libvips, or libheif.
The content that actually matches the headline and product (the libheif RCE disclosure/timeline) is only present in the "release note itself" section, which is Vercel's own blog post.
This looks like a source-mismatch in the data you gave me, possibly the wrong URL got paired with this Vercel announcement. Rather than blend in unrelated material from Anil's blog (which the style guide forbids — "include nothing it does not say" about the actual announcement), I'd rather confirm with you first.
Two options:
1. Write the post using only the Vercel release-note text (the libheif dependency chain, disclosure timeline, mitigation) and treat the `anil.recoil.org` link as unrelated/incorrect.
2. You supply the correct original announcement content/URL and I use that instead.
Which would you like?
Vercel
The platform for frontend developers — deploy, preview, and scale web apps and AI agents with zero config.