Race condition in Next.js - CVE-2025-32421
Published: May 16, 2025 / Updated: November 28, 2025
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information or perform spoofing attack.
The vulnerability exists due to a race condition within the Pages Router. A remote attacker can exploit the race and obtain pageProps data instead of standard HTML code and poison the CDN cache by injecting the response body from a non-cacheable data request (?__nextDataRequest=1) into a normal request that retains cacheable headers, such as Cache-Control: public, max-age=300.
Affected software
IBM Cloud Pak for Security
QRadar Pre-Validation App
QRadar Suite
How to mitigate CVE-2025-32421
IBM Cloud Pak for Security - update to 1.11.9.0
QRadar Pre-Validation App - update to 2.0.2
QRadar Suite - update to 1.11.9.0