GHSA-4633-3j49-mh5q
Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
빠른 조치
GHSA-4633-3j49-mh5q — next: 아래 명령으로 수정 버전으로 올리세요.
npm install next@15.5.21 상세
## Impact
A server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.
This is only an issue when receiving request bodies with a content type charset other than UTF-8. For example, the UTF-16 byte sequences for `삃삃` and `섄섄` in the request body would share the same cache.
## Workarounds
If you cannot upgrade, consider only making fetch requests with UTF-8 bodies (default in Next.js). Applications using Pages Router are not vulnerable.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
참고
- https://github.com/vercel/next.js/security/advisories/GHSA-4633-3j49-mh5q [WEB]
- https://github.com/vercel/next.js/pull/96008 [WEB]
- https://github.com/vercel/next.js/commit/025bf4a5f7b47fb7758c4ebf1c931a61c451c082 [WEB]
- https://github.com/vercel/next.js [PACKAGE]
- https://github.com/vercel/next.js/releases/tag/v15.5.21 [WEB]
- https://github.com/vercel/next.js/releases/tag/v16.2.11 [WEB]