next is vulnerable to Cache Poisoning
63
Medium Risk
Self hosted next Pages Router apps store SSG and ISR responses in a shared cache keyed from the /_next/data path. The path match ignores letter case, so a request for another casing of a route can replace the cached page. Later visitors receive that wrong page until the entry is revalidated. The fix matches /_next/data paths with case sensitivity.
You are affected if you are using a version that falls within the vulnerable range and you self host the Pages Router with SSG or ISR.
next is vulnerable to Cache Poisoning in versions 15.0.0 - 15.5.26 and 16.0.0 - 16.3.7.
Upgrade the next library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.