Intel

AIKIDO-2026-10751

next is vulnerable to Cache Poisoning

Cache PoisoningGHSA-3g8h-86w9-wvmq Published May 7, 2026

37

Low Risk

This Affects:

JSnext
12.2.0 - 15.5.15
Fixed in 15.5.16
16.0.0 - 16.2.4
Fixed in 16.2.5
Are you affected? Scan for Free

TL;DR

Middleware redirect handling can trust externally supplied internal-data headers in affected deployments. A crafted request can alter redirect response shape and poison cached redirect entries when caches do not partition on this signal. Subsequent users can receive unusable cached redirects until expiry. The fix requires validated internal routing state before treating requests as internal data requests.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

next is vulnerable to Cache Poisoning in versions 12.2.0 - 15.5.15 and 16.0.0 - 16.2.4.

How to fix this

Upgrade the next library to the patch version.