VDB
Sign up
MEDIUM5.9

GHSA-wr66-vrwm-5g5x

Denial of Service Vulnerability in next.js

Quick fix

GHSA-wr66-vrwm-5g5x — next: upgrade to the fixed version with the command below.

npm install next@12.0.9

Details

### Impact

Vulnerable code could allow a bad actor to trigger a denial of service attack for anyone running a Next.js app at version >= 12.0.0, and using i18n functionality.

- **Affected:** All of the following must be true to be affected by this CVE - Next.js versions above v12.0.0 - Using next start or a custom server - Using the built-in i18n support - **Not affected:** - Deployments on Vercel (vercel.com) are not affected along with similar environments where invalid requests are filtered before reaching Next.js.

### Patches

A patch has been released, `next@12.0.9`, that mitigates this issue. We recommend all affected users upgrade as soon as possible.

### Workarounds

We recommend upgrading whether you can reproduce or not although you can ensure `/${locale}/_next/` is blocked from reaching the Next.js instance until you upgrade.

### For more information

If you have any questions or comments about this advisory: * Open an issue in [next](https://github.com/vercel/next.js) * Email us at [security@vercel.com](mailto:security@vercel.com)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/next
Introduced in: 12.0.0Fixed in: 12.0.9
Fixnpm install next@12.0.9

References