next is vulnerable to Cache Poisoning
54
Medium Risk
React Server Component request classification and cache-busting interpretation can diverge under shared-cache conditions. An attacker can cause component payload variants to be cached and served for normal URL requests. This can poison cache entries and return incorrect response formats to later users. The fix aligns header interpretation and enforces intended cache-busting behavior for RSC variants.
You are affected if you are using a version that falls within the vulnerable range.
next is vulnerable to Cache Poisoning in versions 14.2.0 - 15.5.15 and 16.0.0 - 16.2.4.
Upgrade the next library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant