GHSA-wff4-fpwg-qqv3

    Dashboard / Vulnerabilities / GHSA-wff4-fpwg-qqv3

    GHSA-wff4-fpwg-qqv3

    Published: 30 Aug 2022Last Modified: 13 Jul 2026

    Summary: Unexpected server crash in Next.js

    Details: ### Impact When specific requests are made to the Next.js server it can cause an `unhandledRejection` in the server which can crash the process to exit in specific Node.js versions with strict `unhandledRejection` handling. - Affected: All of the following must be true to be affected by this CVE - Node.js version above v15.0.0 being used with strict `unhandledRejection` exiting - Next.js version v12.2.3 - Using next start or a [custom server](https://nextjs.org/docs/advanced-features/custom-server) - Not affected: Deployments on Vercel ([vercel.com](https://vercel.com/)) are not affected along with similar environments where `next-server` isn't being shared across requests. ### Patches https://github.com/vercel/next.js/releases/tag/v12.2.4

    Affected packages

    Package

    Name: next

    Purl: pkg:npm/next

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 12.2.3
    Fixed -12.2.4

    Affected versions

    12.2.3

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-wff4-fpwg-qqv3 | CVE-DB