next is vulnerable to Cache Poisoning
63
Medium Risk
The next response cache can store an SSG or ISR result under a key that is not tied to the route that produced it. With a root catch all page, one unauthenticated request can write that shared entry so a different route returns the catch all response. The substituted page stays in place until revalidation, and repeated writes can keep the real page unavailable. The fix keys each cached response to its source route.
You are affected if you are using a version that falls within the vulnerable range and you use a root catch all route together with SSG or ISR.
next is vulnerable to Cache Poisoning in versions 15.0.0 - 15.5.26 and 16.0.0 - 16.3.7.
Upgrade the next library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.