Insecure encryption algorithm In next
Description
A flaw was found in Next.js. React Server Component responses are vulnerable to cache poisoning in deployments that use shared caches without proper response partitioning. An attacker can exploit collisions in the _rsc cache-busting value to poison cache entries. This allows users to receive incorrect response variants for a given URL, potentially leading to information integrity issues.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
npm | 15.5.16, 16.2.5 | ||
rpm rhel10 | - | - | |
rpm rhel7 | - | - | |
rpm rhel8 | - | - | |
rpm rhel9 | - | - | |
rpm rhel8 | - | - | |
rpm rhel9 | - | - | |
rpm rhel10 | - | - |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.