CVE-2023-46298

HIGH

Next.js < 13.4.20-canary.13 - Denial of Service via CDN Cached Prefetch Responses

Title source: llm
STIX 2.1

Description

Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a denial of service to all users requesting the same URL via that CDN.

References (3)

Core 3

Scores

CVSS v3 7.5
EPSS 0.0037
EPSS Percentile 59.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

Status published
Products (3)
npm/next 0.9.9 - 13.4.20-canary.13npm
vercel/next.js 13.4.20 canary0 (13 CPE variants)
vercel/next.js < 13.4.20
Published Oct 22, 2023
Tracked Since Feb 18, 2026