MEDIUM 5.3 npm
Unexpected server crash in Next.js
GHSA-wff4-fpwg-qqv3 · CVE-2022-36046
Published · Modified
Description
Impact
When specific requests are made to the Next.js server it can cause an unhandledRejection in the server which can crash the process to exit in specific Node.js versions with strict unhandledRejection handling.
Affected: All of the following must be true to be affected by this CVE
- Node.js version above v15.0.0 being used with strict
unhandledRejectionexiting - Next.js version v12.2.3
- Using next start or a custom server
- Node.js version above v15.0.0 being used with strict
Not affected: Deployments on Vercel (vercel.com) are not affected along with similar environments where
next-serverisn't being shared across requests.
Patches
Ready to move
Start Securing
Free, no credit card | First findings in minutes