← Back

CVE-2023-46298

nvd nist
Published: Oct 22, 2023Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a denial of service to all users requesting the same URL via that CDN.

Affected (14)

Products: Vercel: Next.js
1 product
Next.js
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Vercel
Before 13.4.20
Version 13.4.20 canary0
Version 13.4.20 canary10
Version 13.4.20 canary11
Version 13.4.20 canary12
Version 13.4.20 canary1
Version 13.4.20 canary2
Version 13.4.20 canary3
Version 13.4.20 canary4
Version 13.4.20 canary5
Version 13.4.20 canary6
Version 13.4.20 canary7
Version 13.4.20 canary8
Version 13.4.20 canary9

References (6)

Source: cve@mitre.org
ExploitIssue TrackingThird Party Advisory
Source: cve@mitre.org
Issue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatch

Timeline

No history available yet.