next is vulnerable to Cache Poisoning
37
Low Risk
RSC cache-busting values can collide in practical deployment conditions that use shared caches. Collisions let attackers poison cache variants so users receive incorrect component responses for a URL. The weakness is insufficient collision resistance in response variant separation. The fix strengthens cache-busting generation to reduce practical collisions and improve variant isolation.
You are affected if you are using a version that falls within the vulnerable range.
next is vulnerable to Cache Poisoning in versions 13.4.6 - 15.5.15 and 16.0.0 - 16.2.4.
Upgrade the next library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant