GHSA-c59h-r6p8-q9wc

Suggest an improvement
Source
https://github.com/advisories/GHSA-c59h-r6p8-q9wc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-c59h-r6p8-q9wc/GHSA-c59h-r6p8-q9wc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-c59h-r6p8-q9wc
Aliases
Published
2023-10-22T03:30:23Z
Modified
2023-11-08T04:13:42.231979Z
Summary
Next.js missing cache-control header may lead to CDN caching empty reply
Details

Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a denial of service to all users requesting the same URL via that CDN. Cloudflare considers these requests cacheable assets.

Database specific
{
    "nvd_published_at": "2023-10-22T03:15:07Z",
    "cwe_ids": [],
    "severity": "LOW",
    "github_reviewed": true,
    "github_reviewed_at": "2023-10-24T19:18:58Z"
}
References

Affected packages

npm / next

Package

Affected ranges

Type
SEMVER
Events
Introduced
0.9.9
Fixed
13.4.20-canary.13