Input validation error in Next.js - CVE-2025-49826

 

Input validation error in Next.js - CVE-2025-49826

Published: July 4, 2025


Vulnerability identifier: #VU112181
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-49826
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an error in the application code that can lead to caching of HTTP 204 response and serving it for static pages. A remote attacker can poison the web application cache and perform a denial of service attack. 


Affected software

Next.js

How to mitigate CVE-2025-49826

Install updates from vendor's website.

Next.js - update to 15.1.8

External References

Related Security Bulletins