Next.JS vulnerability can lead to DoS via cache poisoning
Description
Published to the GitHub Advisory Database
Jul 3, 2025
Reviewed
Jul 3, 2025
Published by the National Vulnerability Database
Jul 3, 2025
Last updated
Jul 3, 2025
Summary
A vulnerability affecting Next.js has been addressed. It impacted versions 15.0.4 through 15.1.8 and involved a cache poisoning bug leading to a Denial of Service (DoS) condition.
Under certain conditions, this issue may allow a HTTP 204 response to be cached for static pages, leading to the 204 response being served to all users attempting to access the page
More details: CVE-2025-49826
Credits
References