Denial of Service Vulnerability in Next.js by Vercel
CVE-2025-49826

7.5HIGH

Key Information:

Vendor

Vercel

Status
Vendor
CVE Published:
3 July 2025

What is CVE-2025-49826?

A cache poisoning vulnerability has been identified in Next.js, a popular React framework for full-stack web applications. This flaw affects various versions of Next.js, specifically from 15.0.4-canary.51 to just prior to 15.1.8. Under specific conditions, this vulnerability allows an HTTP 204 response to be mistakenly cached for static pages, potentially serving this incorrect response to users accessing those pages. This caching issue does not impact applications hosted on Vercel and has been resolved in version 15.1.8, thereby mitigating the risk associated with this vulnerability.

Affected Version(s)

next.js >= 15.0.4-canary.51, < 15.1.8

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-49826 : Denial of Service Vulnerability in Next.js by Vercel