GHSA-3w37-wq28-93x7: Medium severity npm/next vulnerability
Pending use cache fills are shared across requests for the same key without distinguishing Draft Mode requests from regular requests. When two such requests overlap, the second request receives the first request's fill:
- A regular request that overlaps an editor's Draft Mode request receives unpublished content, without any authentication. - A Draft Mode request that overlaps a regular request receives published content instead of the draft.
If the overlapping regular request prerenders a page — for example an on-demand prerender of a route that was not prerendered at build time — the unpublished content can be persisted into the generated page and served to all later visitors of that route until the page is revalidated. Since cached functions can be shared across routes, the poisoned page does not need to be the page the editor is previewing.
Sites are affected if they enable Cache Components (or experimental.useCache) and serve Draft Mode previews whose cached functions return draft-dependent content.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/nextto a version that resolves this vulnerability.Fixed in 16.3.8
Event History
Frequently Asked Questions
Which deployments are affected?
Sites are affected when they enable Cache Components or experimental.useCache and serve Draft Mode previews whose cached functions return content that depends on draft state. Sites that do not combine these conditions are not identified as affected by the available information.
What does exploitation require?
An attacker must cause a regular request to overlap with an editor's Draft Mode request for the same cache key. No authentication is required for the regular request that can receive unpublished content, but the issue depends on timing and user interaction, reflected by the high attack complexity and required user interaction.
When can unpublished content persist beyond the overlapping request?
If the overlapping regular request prerenders a page, such as through an on-demand prerender for a route not prerendered at build time, unpublished content can be written into the generated page. That page may then be served to later visitors until it is revalidated, including when the poisoned route differs from the route the editor was previewing.
What is the practical mitigation if patching cannot happen immediately?
Avoid using cached functions that return draft-dependent content while serving Draft Mode previews. Disabling Cache Components or experimental.useCache removes one of the stated affected conditions.