CVE-2025-49826: Next.js DoS vulnerability via cache poisoning

Published Jul 3, 2025
·
Updated

Summary A vulnerability affecting Next.js has been addressed. It impacted versions 15.0.4 through 15.1.8 and involved a cache poisoning bug leading to a Denial of Service (DoS) condition.

Under certain conditions, this issue may allow a HTTP 204 response to be cached for static pages, leading to the 204 response being served to all users attempting to access the page

More details: CVE-2025-49826

Credits - Allam Rachid zhero; - Allam Yasser (inzo)

Other sources

Next.js is a React framework for building full-stack web applications. From versions 15.0.4-canary.51 to before 15.1.8, a cache poisoning bug leading to a Denial of Service (DoS) condition was found in Next.js. This issue does not impact customers hosted on Vercel. Under certain conditions, this issue may allow a HTTP 204 response to be cached for static pages, leading to the 204 response being served to all users attempting to access the page. This issue has been addressed in version 15.1.8.

NVD

Affected Software

5 affected componentsFixes available
Vercel Next.js>=15.1.0<15.1.8
npm/next>=15.0.4-canary.51<15.1.8
15.1.8
Vercel Next.js Node.js>15.0.4<15.1.8
Vercel Next.js Node.js=15.0.4-canary51
Vercel Next.js Node.js=15.0.4-canary52

Event History

Jul 3, 2025
CVE Published
via MITRE·09:03 PM
Data Sourced
via MITRE·09:03 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·09:14 PM
Data Sourced
via GitHub·09:14 PM
DescriptionSeverityWeaknessAffected Software
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
RemedyAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-49826?

CVE-2025-49826 has been classified as a critical vulnerability due to its potential to cause a Denial of Service (DoS) condition.

2

How do I fix CVE-2025-49826?

To mitigate CVE-2025-49826, you should upgrade Next.js to version 15.1.8 or later.

3

Which versions of Next.js are affected by CVE-2025-49826?

CVE-2025-49826 impacts Next.js versions from 15.0.4 to 15.1.8.

4

What is the nature of the vulnerability in CVE-2025-49826?

CVE-2025-49826 is a cache poisoning vulnerability that can lead to unexpected HTTP response behavior.

5

What potential impact can CVE-2025-49826 have on applications?

CVE-2025-49826 can result in Denial of Service (DoS), affecting the availability of applications built with the affected versions of Next.js.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203