SB2025070419 - Denial of service via cache poisoning in Next.js



SB2025070419 - Denial of service via cache poisoning in Next.js

Published: July 4, 2025

Security Bulletin ID SB2025070419
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Input validation error (CVE-ID: CVE-2025-49826)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an error in the application code that can lead to caching of HTTP 204 response and serving it for static pages. A remote attacker can poison the web application cache and perform a denial of service attack. 


Remediation

Install update from vendor's website.