shipfeedAI news, curated daily

00:36:35 CET
21 MAY00:36:35shipfeed
pull to refreshlast sync
Just in — 30 new
§ feed · storyline

CVE-2025-32421

CVE-2025-32421 details a low-severity cache poisoning vulnerability in Next.js affecting versions 14.2.24 through 15.1.6, exploitable via a race condition between crafted requests.

Apr 22 · · primary fetch1 sourceupdated Apr 22 ·

A low severity cache poisoning vulnerability was discovered in Next.js. This affects versions as a bypass of the previous . The issue happens when an attacker exploits a race condition between two requests — one containing the query parameter and another with the header.>14.2.24?__nextDataRequest=1x-now-route-matches through 14.2.24 through <15.1.6 Stripping the header from all incoming requests at your CDNx-now-route-matches Setting for all responses under riskcache-control: no-store

read full article on vercel.com
§ sources1 publication · timeline below
  1. vercel.comCVE-2025-32421primary