LOW3.7
GHSA-r2fc-ccr8-96c4
Next.js has a Cache poisoning vulnerability due to omission of the Vary header
Quick fix
GHSA-r2fc-ccr8-96c4 — next: upgrade to the fixed version with the command below.
npm install next@15.3.3Details
### Summary
A cache poisoning issue in **Next.js App Router >=15.3.0 and < 15.3.3** may have allowed RSC payloads to be cached and served in place of HTML, under specific conditions involving middleware and redirects. This issue has been fixed in **Next.js 15.3.3**.
Users on affected versions should **upgrade immediately** and **redeploy** to ensure proper caching behavior.
More details: [CVE-2025-49005](https://vercel.com/changelog/cve-2025-49005)
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/vercel/next.js/security/advisories/GHSA-r2fc-ccr8-96c4[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-49005[ADVISORY]
- https://github.com/vercel/next.js/issues/79346[WEB]
- https://github.com/vercel/next.js/pull/79939[WEB]
- https://github.com/vercel/next.js/commit/ec202eccf05820b60c6126d6411fe16766ecc066[WEB]
- https://github.com/vercel/next.js[PACKAGE]
- https://github.com/vercel/next.js/releases/tag/v15.3.3[WEB]
- https://vercel.com/changelog/cve-2025-49005[WEB]