logo

Database

Cross-site request forgery In next

Description

Next.js has cache poisoning in SSG/ISR rendering that leads to cross-user content substitution and persistent denial of service Next.js applications that use a root-level catch-all page together with statically generated or Incremental Static Regeneration routes can have their shared response cache poisoned by a single unauthenticated crafted request.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions