Miggo Logo

CVE-2024-34350: Next.js Vulnerable to HTTP Request Smuggling

7.5

CVSS Score
3.1

Basic Information

EPSS Score
0.6953%
Published
5/9/2024
Updated
7/9/2024
KEV Status
No
Technology
TechnologyJavaScript

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
nextnpm>= 13.4.0, < 13.5.113.5.1

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

### Imp**t In*onsist*nt int*rpr*t*tion o* * *r**t** *TTP r*qu*st m**nt t**t r*qu*sts *r* tr**t** *s *ot* * sin*l* r*qu*st, *n* two s*p*r*t* r*qu*sts *y N*xt.js, l***in* to **syn**roniz** r*spons*s. T*is l** to * r*spons* qu*u* poisonin* vuln*r**ility

Reasoning

No *n*lysis *v*il**l*