CVE-2025-32421: Cache Poisoning Vulnerability in Next.js
A low severity cache poisoning vulnerability was discovered in Next.js versions >14.2.24 through <15.1.6 that exploits a race condition between requests to inject non-cacheable responses into the CDN cache. The issue was patched in versions 15.1.6 and 14.2.24 by stripping the x-now-route-matches header from incoming requests, and Vercel's platform is not affected as it requires explicit cache-control headers.
A low severity cache poisoning vulnerability was discovered in Next.js.
This affects versions as a bypass of the previous . The issue happens when an attacker exploits a race condition between two requests — one containing the query parameter and another with the header.>14.2.24?__nextDataRequest=1x-now-route-matches through <15.1.6CVE-2024-46982
Some CDN providers may cache a response even in the absence of explicit headers, enabling a poisoned response to persist and be served to subsequent users.200 OKcache-control
This vulnerability allows an attacker to poison the CDN cache by injecting the response body from a non-cacheable data request () into a normal request that retains cacheable headers, such as .?__nextDataRequest=1Cache-Control: public, max-age=300
No backend access or privileged escalation is possible through this vulnerability.
This issue was verified using automated tooling that repeatedly triggers the race condition. Successful exploitation depends on precise timing and the presence of a vulnerable CDN configuration. A Python-based proof of concept script was shared by the reporter and used to validate this behavior on live targets prior to the patch.
This issue was patched in and by stripping the header from incoming requests.15.1.614.2.24x-now-route-matches
Applications hosted on by this issue, as the platform does not cache responses based solely on status without explicit headers.Vercel's platform are not affected200 OKcache-control
For self-hosted Next.js deployments unable to upgrade immediately, you can mitigate this vulnerability by:
We strongly recommend only caching responses with explicit headers.cache-control
Thank you to Allam Rachid (zhero;) for the responsible disclosure. They were awarded as part of our bug bounty program.
Summary
Impact
Patches
Credit
Affected Versions
Vercel Platform Mitigation
Workarounds
Next.js versions
>14.2.24through<15.1.6
Stripping the header from all incoming requests at your CDN
x-now-route-matchesSetting for all responses under risk
cache-control: no-store
Source: original entry ↗
More from Vercel
Follow Vercel to get its new changes in your feed and email digest.
OpenAI Decisions API now available on AI Gateway
OpenAI's Decisions API is now accessible through Vercel's AI Gateway with an OpenAI-compatible endpoint, enabling decision models to answer typed questions and return probabilities, choices, and scores for routing, triage, and guardrails use cases. Support is available across the OpenAI SDK, AI SDK, HTTP API, and CLI with the latest versions.
Timestamp attributes now supported in Vercel Flags
Vercel Flags now supports timestamp attributes for entities, allowing you to create time-based targeting rules. Use this feature to run limited-time campaigns, show content between specific dates, or target users based on registration date.
Glyph Cluster now available in stealth on AI Gateway
Glyph Cluster, a reasoning model for coding and long-context analysis, is now available as a stealth model on Vercel's AI Gateway for Pro and Enterprise plan teams with purchased AI Gateway credits at no cost during the stealth period. The model supports function calling, streams responses, and can be accessed via AI SDK, OpenAI-compatible APIs, and coding agents.