Collected research
Next.js and cache poisoning: a quest for the black hole
Three cache-poisoning issues in Next.js, each storing a useless response under a normal cache key and so denying service: the x-middleware-prefetch header returning an empty JSON body for server-rendered pages (CVE-2023-46298); the Rsc header returning a React Server Component payload, since CDNs such as Cloudflare, CloudFront and Akamai ignore or strip Vary; and the internal x-invoke-status header, supplied by a client, overriding the status and returning the error page.
Record
- Published by
- zhero_web_security
- Date
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of zhero_web_security, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .