VDB
Sign up
LOW3.7

GHSA-vfv6-92ff-j949

Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting

Quick fix

GHSA-vfv6-92ff-j949 — next: upgrade to the fixed version with the command below.

npm install next@15.5.16

Details

### Impact

React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared caches with insufficient response partitioning. In affected conditions, collisions in the `_rsc` cache-busting value can allow an attacker to poison cache entries so users receive the wrong response variant for a given URL.

### Fix

We strengthened the `_rsc` cache-busting mechanism to make practical collisions significantly harder and to better separate response variants that should not share cache entries.

### Workarounds

If you cannot upgrade immediately, ensure intermediary caches correctly honor `Vary` for RSC-related request headers, or disable shared caching for affected RSC responses until you can deploy a patched release.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/next
Introduced in: 13.4.6Fixed in: 15.5.16
Fixnpm install next@15.5.16
npm/next
Introduced in: 16.0.0Fixed in: 16.2.5
Fixnpm install next@16.2.5

References