Vercel Cost Security & compliance Performance

Overly broad image remotePatterns wildcard

Part of the Caching & cost check · fix arrives as a guide

What it is

The image configuration allows remote patterns broad enough to match arbitrary hosts — a wildcard hostname or an over-permissive protocol and path.

Why it matters

Anyone can then pass any URL through your image optimiser, so you pay to fetch and transform images for content that is not yours. It is a straightforward way to run up a bill on someone else's account.

How to fix it

Replace the wildcard with the specific hostnames and path prefixes your images actually come from. Each entry should name a host you control or a CDN you deliberately use.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.