Junglewise Threat Intelligence

CVE-2024-46982: Vercel Next.js cache poisoning in pages router

CVE-2024-46982 · Severity: low · CVSS 3.1 · Published 2024-09-17

Technologies: Vercel Next.js. Vendors: Vercel.

Executive brief

Next.js is a popular web framework used to build server-side rendered React applications. An attacker can send specially crafted HTTP requests to poison the cache of non-dynamic server-side rendered pages, causing Next.js to cache content that should not be cached and potentially allowing upstream CDNs to cache poisoned responses. This could lead to users receiving stale or incorrect cached content, affecting site availability and data consistency for applications using the pages router.

Technical details

This vulnerability is a cache poisoning flaw in Next.js's pages router that allows an attacker to manipulate HTTP caching behavior through crafted requests. The vulnerability affects non-dynamic server-side rendered (SSR) routes and causes Next.js to incorrectly send Cache-Control headers (s-maxage=1, stale-while-revalidate) for content that should not be cached, which upstream CDNs may then cache. Attack is network-reachable, requires no authentication or user interaction, and affects versions 13.5.1–13.5.6 and 14.0.0–14.2.9. The app router and Vercel-hosted deployments are unaffected. Patches are available in versions 13.5.7, 14.2.10, and later.

Affected products

  • Vercel Next.js 13.5.1 to 13.5.6, 14.0.0 to 14.2.9

Timeline

  • 2024-09-17: disclosed
  • 2024-09-17: patched: Patched in versions 13.5.7, 14.2.10, and later

References

Related threats