GHSA-mcj8-r9mp-w47p: Medium severity npm/next vulnerability
Next.js applications that use a root-level catch-all page together with statically generated or Incremental Static Regeneration routes can have their shared response cache poisoned by a single unauthenticated crafted request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/nextto a version that resolves this vulnerability.Fixed in 15.5.27 - Upgrade
Upgrade
npm/nextto a version that resolves this vulnerability.Fixed in 16.3.8
Event History
Frequently Asked Questions
Which Next.js applications are exposed to this issue?
Applications are exposed if they use a root-level catch-all page together with statically generated routes or Incremental Static Regeneration routes. The affected software is the npm package next.
What access does an attacker need to poison the cache?
An attacker can trigger the issue with a single crafted request and does not need authentication or user interaction. Exploitation is network-accessible, although the advisory rates attack complexity as high.
What is the impact of successful exploitation?
Successful cache poisoning can affect the integrity and availability of shared cached responses. The provided severity vector indicates no confidentiality impact.