VDB
Sign up
HIGH7.5

GHSA-mg66-mrh9-m8jx

Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components

Quick fix

GHSA-mg66-mrh9-m8jx — next: upgrade to the fixed version with the command below.

npm install next@15.5.16

Details

### Impact

Applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurations, a malicious request can trigger a request-body handling deadlock that leaves connections open for an extended period, consuming file descriptors and server capacity until legitimate users are denied service.

### Fix

We now treat the header used for resuming Partial Prerendered requests as an internal-only header and strip it from untrusted incoming requests. This header should never be accepted directly from external clients.

### Workarounds

If you cannot upgrade immediately, block requests that would be handled by Next.js if they contain the `Next-Resume` header at the edge.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/next
Introduced in: 15.0.0Fixed in: 15.5.16
Fixnpm install next@15.5.16
npm/next
Introduced in: 16.0.0Fixed in: 16.2.5
Fixnpm install next@16.2.5

References