VDB
KO
MEDIUM

GHSA-4633-3j49-mh5q

Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences

Quick fix

GHSA-4633-3j49-mh5q — next: upgrade to the fixed version with the command below.

npm install next@15.5.21

Details

## Impact

A server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.

This is only an issue when receiving request bodies with a content type charset other than UTF-8. For example, the UTF-16 byte sequences for `삃삃` and `섄섄` in the request body would share the same cache.

## Workarounds

If you cannot upgrade, consider only making fetch requests with UTF-8 bodies (default in Next.js). Applications using Pages Router are not vulnerable.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / next
Introduced in: 13.0.0 Fixed in: 15.5.21
Fix npm install next@15.5.21
npm / next
Introduced in: 16.0.0 Fixed in: 16.2.11
Fix npm install next@16.2.11

References