CVE-2023-46298: Vercel Next.js
High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.
Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a denial of service to all users requesting the same URL via that CDN.
Affected products
- Vercel Next.js: before 13.4.20 (fixed in 13.4.20); version 13.4.20 only
Published 2023-10-22. Last modified 2026-06-17.