VDB
Sign up
MEDIUM

GHSA-ggv3-7p47-pfv8

Next.js: HTTP request smuggling in rewrites

Quick fix

GHSA-ggv3-7p47-pfv8 — next: upgrade to the fixed version with the command below.

npm install next@16.1.7

Details

## Summary When Next.js rewrites proxy traffic to an external backend, a crafted `DELETE`/`OPTIONS` request using `Transfer-Encoding: chunked` could trigger request boundary disagreement between the proxy and backend. This could allow request smuggling through rewritten routes.

## Impact An attacker could smuggle a second request to unintended backend routes (for example, internal/admin endpoints), bypassing assumptions that only the configured rewrite destination/path is reachable. This does not impact applications hosted on providers that handle rewrites at the CDN level, such as Vercel.

## Patches The vulnerability originated in an upstream library vendored by Next.js. It is fixed by updating that dependency’s behavior so `content-length: 0` is added only when both `content-length` and `transfer-encoding` are absent, and `transfer-encoding` is no longer removed in that code path.

## Workarounds If upgrade is not immediately possible: - Block chunked `DELETE`/`OPTIONS` requests on rewritten routes at your edge/proxy. - Enforce authentication/authorization on backend routes per our [security guidance](https://nextjs.org/docs/app/guides/data-security).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/next
Introduced in: 16.0.0-beta.0Fixed in: 16.1.7
Fixnpm install next@16.1.7
npm/next
Introduced in: 9.5.0Fixed in: 15.5.13
Fixnpm install next@15.5.13

References