Description
Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a denial of service to all users requesting the same URL via that CDN.
Remediation
References
Related Vulnerabilities
Plone CMS Resource Management Errors Vulnerability (CVE-2012-5506)
Sqlite Integer Overflow or Wraparound Vulnerability (CVE-2020-13434)
MySQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-8286)
phpMyFAQ Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2023-4006)