VDB
Sign up
LOW3.7

GHSA-r2fc-ccr8-96c4

Next.js has a Cache poisoning vulnerability due to omission of the Vary header

Quick fix

GHSA-r2fc-ccr8-96c4 — next: upgrade to the fixed version with the command below.

npm install next@15.3.3

Details

### Summary

A cache poisoning issue in **Next.js App Router >=15.3.0 and < 15.3.3** may have allowed RSC payloads to be cached and served in place of HTML, under specific conditions involving middleware and redirects. This issue has been fixed in **Next.js 15.3.3**.

Users on affected versions should **upgrade immediately** and **redeploy** to ensure proper caching behavior.

More details: [CVE-2025-49005](https://vercel.com/changelog/cve-2025-49005)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/next
Introduced in: 15.3.0Fixed in: 15.3.3
Fixnpm install next@15.3.3

References