PT-2022-15063 · Next.Js · Next.Js

Ijjk

+1

·

Published

2022-01-28

·

Updated

2023-07-24

·

CVE-2022-21721

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Next.js versions 12.0.0 through 12.0.8
Description The issue allows a bad actor to trigger a denial of service attack for anyone using i18n functionality. To be affected, one must use next start or a custom server and the built-in i18n support. Deployments on Vercel, along with similar environments where invalid requests are filtered before reaching Next.js, are not affected.
Recommendations For Next.js versions 12.0.0 through 12.0.8, upgrade to next@12.0.9 to mitigate the issue. As a temporary workaround, ensure /${locale}/ next/ is blocked from reaching the Next.js instance until it becomes feasible to upgrade.

Exploit

Fix

RCE

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2022-21721
GHSA-WR66-VRWM-5G5X

Affected Products

Next.Js