PT-2025-27836 · Next.Js · Next.Js

·

CVE-2025-49826

·

Published

2025-07-03

·

Updated

2025-08-09

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Next.js versions 15.0.4-canary.51 through 15.1.7
Description Next.js is susceptible to a cache poisoning issue that can lead to a Denial of Service (DoS) condition. This flaw allows attackers to manipulate the caching of HTTP responses, potentially serving cached HTTP 204 responses for static pages to all users, rendering the pages inaccessible. The issue impacts self-hosted deployments but does not affect customers hosted on Vercel.
Recommendations Update to Next.js version 15.1.8 or later.

Exploit

Fix

DoS

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-16414
CVE-2025-49826
GHSA-67RR-84XM-4C7R

Affected Products

Next.Js