Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. next
  4. ›
  5. CVE-2025-32421

CVE-2025-32421: Next.js Race Condition to Cache Poisoning

May 15, 2025

Summary We received a responsible disclosure from Allam Rachid (zhero) for a low-severity race-condition vulnerability in Next.js. This issue only affects the Pages Router under certain misconfigurations, causing normal endpoints to serve pageProps data instead of standard HTML.

Learn more here

Credit Thank you to Allam Rachid (zhero) for the responsible disclosure. This research was rewarded as part of our bug bounty program.

References

  • github.com/advisories/GHSA-qpjv-v59x-3qc4
  • github.com/vercel/next.js
  • github.com/vercel/next.js/security/advisories/GHSA-qpjv-v59x-3qc4
  • nvd.nist.gov/vuln/detail/CVE-2025-32421
  • vercel.com/changelog/cve-2025-32421

Code Behaviors & Features

Detect and mitigate CVE-2025-32421 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 14.2.24, all versions starting from 15.0.0 before 15.1.6

Fixed versions

  • 14.2.24
  • 15.1.6

Solution

Upgrade to versions 14.2.24, 15.1.6 or above.

Impact 3.7 LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Source file

npm/next/CVE-2025-32421.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 19 Aug 2025 12:18:42 +0000.