Junglewise Threat Intelligence

CVE-2024-39693: Vercel Next.js denial of service condition

CVE-2024-39693 · Severity: low · CVSS 3.1 · Published 2024-07-10

Technologies: Vercel Next.js. Vendors: Vercel.

Executive brief

Next.js is a popular React framework used to build web applications. A flaw in versions 13.3.1 through 13.4.x allows unauthenticated attackers to crash the server by triggering excessive resource consumption, resulting in service unavailability for all users of affected deployments.

Technical details

This vulnerability is classified as an uncontrolled resource consumption flaw (CWE-400) that triggers a denial of service condition in Next.js. The flaw was introduced in version 13.3.1 and affects all versions prior to 13.5.0. Exploitation requires no authentication or user interaction and can be triggered remotely over the network, causing the affected server to crash. The vulnerability impacts the availability of the application, preventing legitimate users from accessing the service. A patch is available in Next.js 13.5.0 and later.

Affected products

  • Vercel Next.js 13.3.1 to 13.4.x

Timeline

  • 2024-07-10: disclosed

References

Related threats