CyberRota Analysis
AI-GeneratedNext.js versions 16.3.0 to 16.3.7 are vulnerable due to improper caching of `use cache` handlers, which can lead to the leakage of return values across different root parameters. This vulnerability may allow a response for one root parameter to inadvertently serve content intended for another, potentially exposing sensitive information. Developers using affected versions should prioritize upgrading to version 16.3.8 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Next.js versions from 16.3.0 to 16.3.7 warm `use cache` handlers using `next/root-params` and can leak their return value to pages with different root params. With Cache Components enabled (cacheComponents: true), a 'use cache' function that calls another 'use cache' function that reads a root param can be keyed incorrectly when the inner call is served from an existing entry: the enclosing function's cache key then omits that root param. The enclosing entry is written once and reused for all root param values, so a response for one root param value can serve content produced for a different value — whether the page is prerendered at build time or at runtime, or rendered dynamically. Shared cache headers let downstream caches redistribute the content further. What values are leaked cannot be attacker controlled. Which value's content is served depends only on which invocation wrote the entry first. This has been patched in 16.3.8.
Related CVEs
Other vulnerabilities affecting the same vendor(s)