CVE-2023-46298
22.10.2023, 03:15
Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a denial of service to all users requesting the same URL via that CDN.Enginsight
Vendor | Product | Version |
---|---|---|
vercel | next.js | 𝑥 < 13.4.20 |
vercel | next.js | 13.4.20:canary0 |
vercel | next.js | 13.4.20:canary1 |
vercel | next.js | 13.4.20:canary10 |
vercel | next.js | 13.4.20:canary11 |
vercel | next.js | 13.4.20:canary12 |
vercel | next.js | 13.4.20:canary2 |
vercel | next.js | 13.4.20:canary3 |
vercel | next.js | 13.4.20:canary4 |
vercel | next.js | 13.4.20:canary5 |
vercel | next.js | 13.4.20:canary6 |
vercel | next.js | 13.4.20:canary7 |
vercel | next.js | 13.4.20:canary8 |
vercel | next.js | 13.4.20:canary9 |
𝑥
= Vulnerable software versions
References