Next.js is a React framework for building full-stack web applications. In versions before 14.2.31 and from 15.0.0 to before 15.4.5, Next.js Image Optimization API routes are affected by cache key confusion. When images returned from API routes vary based on request headers (such as Cookie or Authorization), these responses could be incorrectly cached and served to unauthorized users due to a cache key confusion bug. This vulnerability has been fixed in Next.js versions 14.2.31 and 15.4.5. All users are encouraged to upgrade if they use API routes to serve images that depend on request headers and have image optimization enabled.
Metrics
Affected Vendors & Products
References
History
Tue, 02 Sep 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 01 Sep 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Sun, 31 Aug 2025 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Vercel
Vercel next.js |
|
Vendors & Products |
Vercel
Vercel next.js |
Fri, 29 Aug 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Next.js is a React framework for building full-stack web applications. In versions before 14.2.31 and from 15.0.0 to before 15.4.5, Next.js Image Optimization API routes are affected by cache key confusion. When images returned from API routes vary based on request headers (such as Cookie or Authorization), these responses could be incorrectly cached and served to unauthorized users due to a cache key confusion bug. This vulnerability has been fixed in Next.js versions 14.2.31 and 15.4.5. All users are encouraged to upgrade if they use API routes to serve images that depend on request headers and have image optimization enabled. | |
Title | Next.js Affected by Cache Key Confusion for Image Optimization API Routes | |
Weaknesses | CWE-524 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-02T19:23:39.835Z
Reserved: 2025-08-19T15:16:22.916Z
Link: CVE-2025-57752

Updated: 2025-09-02T19:23:34.653Z

Status : Awaiting Analysis
Published: 2025-08-29T22:15:31.963
Modified: 2025-09-02T15:55:35.520
Link: CVE-2025-57752


Updated: 2025-08-31T08:41:33Z