Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19910 | Next.JS vulnerability can lead to DoS via cache poisoning |
Github GHSA |
GHSA-67rr-84xm-4c7r | Next.JS vulnerability can lead to DoS via cache poisoning |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 10 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:* cpe:2.3:a:vercel:next.js:15.0.4:canary51:*:*:*:node.js:*:* cpe:2.3:a:vercel:next.js:15.0.4:canary52:*:*:*:node.js:*:* |
Tue, 08 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Jul 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 03 Jul 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Next.js is a React framework for building full-stack web applications. From versions 15.1.0 to before 15.1.8, a cache poisoning bug leading to a Denial of Service (DoS) condition was found in Next.js. This issue does not impact customers hosted on Vercel. Under certain conditions, this issue may allow a HTTP 204 response to be cached for static pages, leading to the 204 response being served to all users attempting to access the page. This issue has been addressed in version 15.1.8. | Next.js is a React framework for building full-stack web applications. From versions 15.0.4-canary.51 to before 15.1.8, a cache poisoning bug leading to a Denial of Service (DoS) condition was found in Next.js. This issue does not impact customers hosted on Vercel. Under certain conditions, this issue may allow a HTTP 204 response to be cached for static pages, leading to the 204 response being served to all users attempting to access the page. This issue has been addressed in version 15.1.8. |
Thu, 03 Jul 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Next.js is a React framework for building full-stack web applications. From versions 15.1.0 to before 15.1.8, a cache poisoning bug leading to a Denial of Service (DoS) condition was found in Next.js. This issue does not impact customers hosted on Vercel. Under certain conditions, this issue may allow a HTTP 204 response to be cached for static pages, leading to the 204 response being served to all users attempting to access the page. This issue has been addressed in version 15.1.8. | |
| Title | Next.js DoS vulnerability via cache poisoning | |
| Weaknesses | CWE-444 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-07-08T14:33:21.671Z
Reserved: 2025-06-11T14:33:57.799Z
Link: CVE-2025-49826
Updated: 2025-07-08T14:33:18.505Z
Status : Analyzed
Published: 2025-07-03T21:15:27.287
Modified: 2025-09-10T15:28:32.130
Link: CVE-2025-49826
OpenCVE Enrichment
Updated: 2025-07-06T22:16:22Z
EUVD
Github GHSA