vulns.co
/
GKData.io MCP

zhero_web_security · 1 min read

Next.js: response metadata must preserve representation boundaries

Researchers describe client-supplied metadata becoming authoritative response metadata through unusual middleware header copying. This changed how a dynamic App Router representation was interpreted; an external shared cache preserved the mismatch for later visitors. They report stored browser script execution in an anonymized production application. The core failure is a representation contract losing its integrity when request data controls response meaning.

Open the reference Research PaperReviewed 2026-10-04

How to use this reference

Keep ownership of response interpretation with the component that creates the body. Next.js documentation warns that copying incoming headers into responses can override framework expectations and recommends selective forwarding. Editorial lesson: review body format, response metadata and cache variation as one contract. Data safe for one consumer may be unsafe for another; persistence does not repair that mismatch. An application review should distinguish intended upstream request metadata from browser-facing response metadata and document which layer owns each decision.

Before reading

  • HTTP request and response metadata, content negotiation and shared-cache concepts
  • Basic server-rendered framework and browser interpretation concepts

Context and limits

  • Exposure requires the described header-copying behavior, a dynamic representation and external caching. This is configuration-specific; the article does not establish a universal Next.js flaw.
  • The reported effect still requires a visitor to load affected content. The publication supplies no independently corroborated vendor incident account, verified fixed version or remediation date.
  • The unspecified five-figure award establishes neither an exact amount nor a currency. This resource does not qualify as an award-backed report.

Sources and provenance

  1. Re:CACHE: Next.js response-reflection research zhero_web_security · reviewed 2026-10-04
  2. NextResponse documentation: request forwarding and response headers Next.js · reviewed 2026-10-04

Record reviewed 2026-10-04. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software