CVE-2022-21721: Uncontrolled Resource Consumption
(updated )
Next. one must use next start or a custom server and the built-in i18n support. Deployments on Vercel, along with similar environments where invalid requests are filtered before reaching Next.js, are not affected. A patch has been released, next@12.0.9
, that mitigates this issue. As a workaround, one may ensure /${locale}/_next/
is blocked from reaching the Next.js instance until it becomes feasible to upgrade.
References
Detect and mitigate CVE-2022-21721 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →