CVE-2025-49826 – next
Package
Manager: npm
Name: next
Vulnerable Version: >=15.0.4-canary.51 <15.1.8
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS: 0.00019 pctl0.03248
Details
Next.JS vulnerability can lead to DoS via cache poisoning ### Summary A vulnerability affecting Next.js has been addressed. It impacted versions 15.0.4 through 15.1.8 and involved a cache poisoning bug leading to a Denial of Service (DoS) condition. Under certain conditions, this issue may allow a HTTP 204 response to be cached for static pages, leading to the 204 response being served to all users attempting to access the page More details: [CVE-2025-49826](https://vercel.com/changelog/cve-2025-49826) ## Credits - Allam Rachid [zhero;](https://zhero-web-sec.github.io/research-and-things/) - Allam Yasser (inzo)
Metadata
Created: 2025-07-03T21:14:48Z
Modified: 2025-07-03T21:49:52Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-67rr-84xm-4c7r/GHSA-67rr-84xm-4c7r.json
CWE IDs: ["CWE-444"]
Alternative ID: GHSA-67rr-84xm-4c7r
Finding: F110
Auto approve: 1