Junglewise Threat Intelligence

CVE-2022-36046: PYSEC-2022-43188 - Next.js is a React framework that can provide building blocks to create web applications. All of the following must be true to be affected b

CVE-2022-36046 · Severity: low · CVSS 3.1 · Published 2022-08-31

Technologies: Vercel Next.js. Vendors: PyPI, Vercel.

Executive brief

Next.js is a popular web application framework used to build production web servers. In version 12.2.3, specific malformed requests can trigger an unhandled promise rejection that crashes the entire server process when running on Node.js v15+, causing service downtime and potential data loss if the process terminates unexpectedly during request handling.

Technical details

This vulnerability is a denial-of-service condition caused by an unhandled promise rejection (CWE-248) in Next.js 12.2.3 when processing specific requests. The root cause is insufficient error handling in request processing logic that leaves promises unhandled. The attack requires network access to the server and is triggered by sending crafted HTTP requests to the Next.js application. The vulnerability only affects self-hosted deployments using "next start" or custom servers running on Node.js v15.0.0 or later with strict unhandledRejection handling enabled (the default behavior). An attacker can reliably crash the server process, causing temporary unavailability. The patch was released in version 12.2.4.

Affected products

  • Vercel Next.js 12.2.3

Timeline

  • 2022-08-24: disclosed
  • 2022-08-30: advisory
  • 2022-08-31: patched: v12.2.4 released

References

Related threats