AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Duplicate Location And X-Nextjs-Stale-Time Headers In Next.Js 15.4.1+ When Using Redirect/PermanentRedirect With Force-Static

Next.js 15.4.1 introduced a regression where redirects combined with dynamic 'force-static' cause duplicate Location and x-nextjs-stale-time response headers. This can lead to malformed redirect URLs (e.g., '/redirect,/redirect') depending on how clients process the duplicate header.

highConfidence 90%Next.jsAffected V15.4.1Affected V15.4.2Affected V15.4.3Affected V15.4.4

Origin Analysis

Two separate code paths add the Location and x-nextjs-stale-time headers: one via NodeNextResponse.setHeader (which replaces existing values) and another via native appendHeader (which appends without checking existing values). Since 15.4.1, the appendHeader path is triggered alongside the setHeader path, resulting in duplicate values.
1. Build and start a Next.js project using version 15.4.1 or later. 2. Create a route that uses redirect() or permanentRedirect() and is marked as dynamic 'force-static'. 3. Visit that route with network console open. 4. Observe that the response contains duplicated Location and x-nextjs-stale-time headers.

Fixing Code Block

Edge Case Audit

This fix may alter behavior if middleware or other code intentionally appended multiple Location headers for some proxy scenario, but such usage is non-standard. It is safe for typical applications. If unexpected issues arise, revert the patch and consider checking if headers are already sent before calling setHeader. Also verify with streaming responses to avoid setting headers after they have been sent.

Ecosystem Topology