Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 npm

Next.JS vulnerability can lead to DoS via cache poisoning

GHSA-67rr-84xm-4c7r · CVE-2025-49826

Published · Modified

Description

Summary

A vulnerability affecting Next.js has been addressed. It impacted versions 15.0.4 through 15.1.8 and involved a cache poisoning bug leading to a Denial of Service (DoS) condition.

Under certain conditions, this issue may allow a HTTP 204 response to be cached for static pages, leading to the 204 response being served to all users attempting to access the page

More details: CVE-2025-49826

Credits

  • Allam Rachid zhero;
  • Allam Yasser (inzo)

Ready to move

Start Securing

Free, no credit card | First findings in minutes