Denial of Service Vulnerability in Next.js by Vercel
CVE-2023-46298
7.5HIGH
What is CVE-2023-46298?
Next.js prior to version 13.4.20-canary.13 contains a vulnerability due to the absence of a cache-control header, which can lead to empty prefetch responses being cached by Content Delivery Networks (CDNs). This caching behavior may inadvertently cause a denial of service for users attempting to access the same URL via the CDN, resulting in interruptions in service and accessibility issues.