CVE-2025-32421 is a race-condition flaw in Next.js Pages Router deployments. In affected self-hosted configurations, request handling and caching can be manipulated so that endpoints ordinarily expected to return HTML instead return cached pageProps data. The issue is addressed in Next.js 14.2.24 and 15.1.6 by removing the x-now-route-matches request header before routing and response caching behavior is processed.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (PoC) lab for CVE-2025-32421, a race condition cache poisoning vulnerability affecting Next.js deployments behind misconfigured CDNs. The lab consists of three main components: a backend (Node.js/Express) simulating Next.js behavior, a proxy (nginx) acting as a vulnerable CDN, and an exploit script (Python) that automates the attack. The backend exposes two types of responses at '/': a normal HTML page and a JSON data response (when the '__nextDataRequest=1' query parameter and 'x-now-route-matches' header are present), with the latter containing a secret token. The nginx proxy is intentionally misconfigured to ignore backend cache-control headers and to use a cache key that does not distinguish between the two request types, making it vulnerable to cache poisoning. The exploit script launches concurrent requests to both endpoints, attempting to poison the cache so that the secret JSON data is served to normal HTML requests. The repository includes Dockerfiles and a docker-compose.yml for easy setup, as well as a setup.sh script to build and launch the environment. The main exploit capability is automated cache poisoning via a race condition, and the main fingerprintable endpoints are the proxy at http://localhost:8080/ and its data variant. The repository is structured as a self-contained lab for demonstrating and testing this specific vulnerability.
This repository is a comprehensive exploit lab for CVE-2025-32421, a critical race condition vulnerability in Next.js (15.0.4 and other affected versions). The exploit demonstrates how an attacker can leverage a race condition in the Next.js promise batcher (via the '/_error-0' cache key) to expose sensitive server-side data to the client. The lab also chains this with Cross-Site Scripting (XSS) by injecting malicious payloads through unsanitized cookies (such as 'theme' or 'userInput'), which are rendered using 'dangerouslySetInnerHTML' in the React app. The repository is structured as a Next.js application with custom pages and several exploit scripts in the 'exploits/' directory: - 'cve-2025-32421-eclipse-exploit.js': Automates the race condition attack to leak data. - 'cve-2025-32421-xss-eclipse.js': Combines XSS and the Eclipse technique for persistent data exfiltration and privilege escalation. - 'cve-2025-32421-demo.js' and 'cve-2025-32421-simple-demo.js': Provide basic and simplified demonstrations of the vulnerability. Key endpoints include the main application at 'http://localhost:3001', the '/_error' page (targeted for cache collision), and example exfiltration endpoints ('/api/leak', '/api/exfiltrate'). The application exposes sensitive data such as monitoring configuration (Sentry DSN, API keys), admin status, and session/user IDs in the client-side HTML, which can be extracted by an attacker using the provided exploits. The lab is intended for educational and research purposes only, and includes detailed documentation and mitigation advice.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.