Web Hack List

Collected research

Next.js and cache poisoning: a quest for the black hole

Three cache-poisoning issues in Next.js, each storing a useless response under a normal cache key and so denying service: the x-middleware-prefetch header returning an empty JSON body for server-rendered pages (CVE-2023-46298); the Rsc header returning a React Server Component payload, since CDNs such as Cloudflare, CloudFront and Akamai ignore or strip Vary; and the internal x-invoke-status header, supplied by a client, overriding the status and returning the error page.

Record

Published by
zhero_web_security
Date
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of zhero_web_security, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .