Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2025-19911 | Next.js has a Cache poisoning vulnerability due to omission of the Vary header | 
  Github GHSA | 
                GHSA-r2fc-ccr8-96c4 | Next.js has a Cache poisoning vulnerability due to omission of the Vary header | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 10 Sep 2025 19:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Vercel vercel
         | 
|
| CPEs | cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:* cpe:2.3:a:vercel:vercel:*:*:*:*:*:*:*:*  | 
|
| Vendors & Products | 
        
        Vercel vercel
         | 
Tue, 08 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Fri, 04 Jul 2025 00:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | |
| Metrics | 
        
        
        threat_severity
         
  | 
    
        
        
        threat_severity
         
  | 
Thu, 03 Jul 2025 21:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Next.js is a React framework for building full-stack web applications. In Next.js App Router from 15.3.0 to before 15.3.3 and Vercel CLI from 41.4.1 to 42.2.0, a cache poisoning vulnerability was found. The issue allowed page requests for HTML content to return a React Server Component (RSC) payload instead under certain conditions. When deployed to Vercel, this would only impact the browser cache, and would not lead to the CDN being poisoned. When self-hosted and deployed externally, this could lead to cache poisoning if the CDN does not properly distinguish between RSC / HTML in the cache keys. This issue has been resolved in Next.js 15.3.3. | |
| Title | Next.js cache poisoning due to omission of Vary header | |
| Weaknesses | CWE-444 | |
| References | 
         | 
        
  | 
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-07-08T14:34:12.642Z
Reserved: 2025-05-29T16:34:07.175Z
Link: CVE-2025-49005
Updated: 2025-07-08T14:34:04.406Z
Status : Analyzed
Published: 2025-07-03T21:15:26.787
Modified: 2025-09-10T19:14:45.153
Link: CVE-2025-49005
                        OpenCVE Enrichment
                    Updated: 2025-07-06T22:16:21Z
 EUVD
 Github GHSA