Next.js Affected by Cache Key Confusion for Image Optimization API Routes
Published Aug 29, 2025
6.2
MEDIUMCVSS 3.1
EPSS 0.35%
Description
Next.js is a React framework for building full-stack web applications. In versions before 14.2.31 and from 15.0.0 to before 15.4.5, Next.js Image Optimization API routes are affected by cache key confusion. When images returned from API routes vary based on request headers (such as Cookie or Authorization), these responses could be incorrectly cached and served to unauthorized users due to a cache key confusion bug. This vulnerability has been fixed in Next.js versions 14.2.31 and 15.4.5. All users are encouraged to upgrade if they use API routes to serve images that depend on request headers and have image optimization enabled.
Affected products
-
Affected
- < 14.2.31
- ≥ 15.0.0, < 15.4.5
No data.
Red Hat Enterprise Linux 10
firefox
Fix deferred
Red Hat Enterprise Linux 10
thunderbird
Fix deferred
Red Hat Enterprise Linux 7
firefox
Fix deferred
Red Hat Enterprise Linux 8
firefox
Fix deferred
Red Hat Enterprise Linux 8
thunderbird
Fix deferred
Red Hat Enterprise Linux 9
dotnet7.0
Fix deferred
Red Hat Enterprise Linux 9
firefox
Fix deferred
Red Hat Enterprise Linux 9
thunderbird
Fix deferred
Red Hat Trusted Artifact Signer
rhtas/rekor-search-ui-rhel9
Fix deferred
streams for Apache Kafka 2
com.github.streamshub-console
Fix deferred
streams for Apache Kafka 3
com.github.streamshub-console
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | firefox | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | thunderbird | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | firefox | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | firefox | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | thunderbird | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | dotnet7.0 | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | firefox | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | thunderbird | Fix deferred | n/a |
| Red Hat Trusted Artifact Signer | rhtas/rekor-search-ui-rhel9 | Fix deferred | n/a |
| streams for Apache Kafka 2 | com.github.streamshub-console | Fix deferred | n/a |
| streams for Apache Kafka 3 | com.github.streamshub-console | Fix deferred | n/a |
next
npm
Introduced 0.9.9 Fixed 14.2.31next
npm
Introduced 15.0.0 Fixed 15.4.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | next | 0.9.9 | 14.2.31 |
| npm | next | 15.0.0 | 15.4.5 |
Remediation
Red Hat statement
This vulnerability is considered Moderate because it only impacts applications that both (1) serve images through API routes where responses vary based on sensitive request headers, and (2) have image optimization enabled. In most common Next.js deployments, static images or header-independent responses are used, meaning the bug has no effect. Additionally, the exposure is limited to cached image content rather than direct access to underlying APIs or application data. Since it does not allow arbitrary code execution, privilege escalation, or broad data leakage by default, the impact is constrained to specific configurations, making it a Moderate issue rather than a Important flaw.
Red Hat mitigation
As a mitigation, developers/admins should avoid serving images that depend on sensitive request headers (such as Cookie or Authorization) through the Image Optimization API. Instead, these images can be served directly without optimization or with caching disabled to prevent unintended exposure to unauthorized users.
References (10)
- https://access.redhat.com/security/cve/CVE-2025-57752 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2392060 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-28624 Advisory
- https://github.com/advisories/GHSA-g5qg-72qw-gw5v Advisory
- https://github.com/vercel/next.js/commit/6b12c60c61ee80cb0443ccd20de82ca9b4422ddd x_refsource_MISCPatch
- https://github.com/vercel/next.js/pull/82114 x_refsource_MISCPatch
- https://github.com/vercel/next.js/security/advisories/GHSA-g5qg-72qw-gw5v x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-57752
- https://vercel.com/changelog/cve-2025-57752 x_refsource_MISCVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2025-57752
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-57752 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2392060 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-28624 | Advisory | |
| https://github.com/advisories/GHSA-g5qg-72qw-gw5v | Advisory | |
| https://github.com/vercel/next.js/commit/6b12c60c61ee80cb0443ccd20de82ca9b4422ddd | x_refsource_MISCPatch | |
| https://github.com/vercel/next.js/pull/82114 | x_refsource_MISCPatch | |
| https://github.com/vercel/next.js/security/advisories/GHSA-g5qg-72qw-gw5v | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-57752 | ||
| https://vercel.com/changelog/cve-2025-57752 | x_refsource_MISCVendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2025-57752 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub