CVE-2024-46982 is a cache poisoning vulnerability in Next.js affecting the pages router for non-dynamic server-side rendered routes. A crafted HTTP request can cause a route that is normally intended to be non-cacheable to be treated as cacheable, resulting in a response with cache directives such as s-maxage=1 and stale-while-revalidate. This can cause intermediary caches and some upstream CDNs to store and later serve poisoned content for requests to the affected route. The issue affects Next.js versions 13.5.1 through 13.5.6 and 14.2.0 through 14.2.9. The app router is not affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository is a minimal Next.js (pages router) application intended to reproduce CVE-2024-46982 (stored XSS via cache poisoning). Structure: standard Next.js config (next.config.mjs), TypeScript config (tsconfig.json), and pages under src/pages. The key PoC logic is in src/pages/poc.tsx: getServerSideProps reads the incoming request's 'user-agent' header and returns it in props (user-controlled input). The README describes two exploitation flows that rely on Next.js-specific request toggles: (1) requesting /poc?__nextDataReq=1 with header x-now-route-matches: 1 and a script tag in User-Agent, and (2) requesting /_next/data/<BUILD_ID>/poc.json similarly. These requests are intended to produce cacheable responses (Cache-Control: s-maxage=1, stale-while-revalidate) that can be stored by an intermediary cache/CDN and then served to subsequent normal visitors (e.g., visiting http://localhost:3000), resulting in stored XSS. No automated exploit script is included; exploitation is performed manually via crafted HTTP requests as documented.
This repository provides an operational exploit for CVE-2024-46982, a cache poisoning vulnerability in Next.js. The exploit is implemented in Go (main.go) and is accompanied by a Nuclei-compatible YAML template (cve-2024-46982.yaml) for automated scanning. The exploit works by sending HTTP GET requests to Next.js endpoints (such as /index or /poc) with a malicious payload in the User-Agent header and a special x-now-route-matches header. It attempts to poison the cache so that the payload is stored and reflected in subsequent responses, potentially leading to stored XSS, DoS, or data leakage. The tool can process multiple targets and payloads, reporting which endpoints are vulnerable. The repository is structured with clear entry points (main.go for the Go exploit, cve-2024-46982.yaml for Nuclei), and includes a README with detailed usage instructions. The main attack vector is network-based, targeting HTTP endpoints on vulnerable Next.js applications.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Next.js cache poisoning vulnerability affecting server-side rendered data routes, where requests using __nextDataReq=1 or /_next/data/{buildId}/{file}.json can cause attacker-controlled JSON responses to be cached and then served for subsequent page requests.
Referenced only as a previous vulnerability in Vercel's security history; no technical details are provided in the content.
A React Server Components / Next.js-related prototype pollution issue leading to remote code execution, observed here as automated scanning/exploitation attempts using multipart POST bodies with __proto__ manipulation and OAST callbacks.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.