High severity7.5NVD Advisory· Published May 14, 2024· Updated Jun 17, 2026
CVE-2024-34350
CVE-2024-34350
Description
Next.js is a React framework that can provide building blocks to create web applications. Prior to 13.5.1, an inconsistent interpretation of a crafted HTTP request meant that requests are treated as both a single request, and two separate requests by Next.js, leading to desynchronized responses. This led to a response queue poisoning vulnerability in the affected Next.js versions. For a request to be exploitable, the affected route also had to be making use of the rewrites feature in Next.js. The vulnerability is resolved in Next.js 13.5.1 and newer.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nextnpm | >= 13.4.0, < 13.5.1 | 13.5.1 |
Affected products
3Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-77r5-gw3j-2mpfghsaADVISORY
- github.com/vercel/next.js/security/advisories/GHSA-77r5-gw3j-2mpfnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-34350ghsaADVISORY
- github.com/vercel/next.js/commit/44eba020c615f0d9efe431f84ada67b81576f3f5ghsaWEB
- github.com/vercel/next.js/compare/v13.5.0...v13.5.1ghsaWEB
News mentions
0No linked articles in our index yet.