SB2025070417 - Cache poisoning attack in Next.js



SB2025070417 - Cache poisoning attack in Next.js

Published: July 4, 2025

Security Bulletin ID SB2025070417
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Input validation error (CVE-ID: CVE-2025-49005)

The vulnerability allows a remote attacker to perform a cache poisoning attack.

The vulnerability exists due to omission of Vary HTTP header when creating cache data in App Router. A remote attacker can force the application to cache RSC payloads and serve them in place of HTML code under specific conditions involving middleware and redirects.


Remediation

Install update from vendor's website.