This release contains security fixes for the following advisories:
High:
Medium:
- Information disclosure in Next.js App Router metadata image routes via dynamicParams bypass
- Cache poisoning of SSG and ISR pages in self-hosted Next.js applications
- Cache poisoning in Next.js SSG/ISR rendering leads to cross-user content substitution and persistent denial of service
- Pending
use cachefill can leak Draft Mode content into regular responses and persisted pages - Cache leak across root param values in nested 'use cache' functions
Low: