Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a denial of service to all users requesting the same URL via that CDN.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| next(npm) | 0.9.9 | 13.4.20-canary.13 | N/A |
CVSS Metrics