Launch Week Day 1: Announcing Security Design Review
LOW 3.7 npm

Next.js Race Condition to Cache Poisoning

GHSA-qpjv-v59x-3qc4 · CVE-2025-32421

Published · Modified

Description

Summary
We received a responsible disclosure from Allam Rachid (zhero) for a low-severity race-condition vulnerability in Next.js. This issue only affects the Pages Router under certain misconfigurations, causing normal endpoints to serve pageProps data instead of standard HTML.

Learn more here

Credit
Thank you to Allam Rachid (zhero) for the responsible disclosure. This research was rewarded as part of our bug bounty program.

Ready to move

Start Securing

Free, no credit card | First findings in minutes