Denial of Service Vulnerability in Next.js by Vercel
CVE-2025-49826
7.5HIGH
What is CVE-2025-49826?
A cache poisoning vulnerability has been identified in Next.js, a popular React framework for full-stack web applications. This flaw affects various versions of Next.js, specifically from 15.0.4-canary.51 to just prior to 15.1.8. Under specific conditions, this vulnerability allows an HTTP 204 response to be mistakenly cached for static pages, potentially serving this incorrect response to users accessing those pages. This caching issue does not impact applications hosted on Vercel and has been resolved in version 15.1.8, thereby mitigating the risk associated with this vulnerability.
Affected Version(s)
next.js >= 15.0.4-canary.51, < 15.1.8