next is vulnerable to Cache Poisoning
37
Low Risk
Middleware redirect handling can trust externally supplied internal-data headers in affected deployments. A crafted request can alter redirect response shape and poison cached redirect entries when caches do not partition on this signal. Subsequent users can receive unusable cached redirects until expiry. The fix requires validated internal routing state before treating requests as internal data requests.
You are affected if you are using a version that falls within the vulnerable range.
next is vulnerable to Cache Poisoning in versions 12.2.0 - 15.5.15 and 16.0.0 - 16.2.4.
Upgrade the next library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant