AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Router State Header Parsing Fails After Upgrade From 16.1 To 16.2 On Dynamic Routes

Soft navigation breaks with a 500 error when a client that loaded a 16.1 app navigates after a server upgrade to 16.2, because the router state header format/encoding changed and the new server parser throws instead of falling back to a full navigation. The issue only occurs when at least one layout or page is dynamically rendered (e.g., uses cookies()).

highConfidence 82%Next.jsAffected V16.2.0Affected V16.2.1-Canary.45

Origin Analysis

Between Next.js 16.1 and 16.2, the format or encoding of the router state header (sent on soft navigations) was changed without backward compatibility. Dynamic rendering forces the server to process this header from stale 16.1 clients, and the 16.2 parser cannot parse the legacy format, throwing an unhandled error and returning 500 instead of gracefully ignoring the header and performing a full navigation.
1. Clone the reproduction repo and install dependencies with Next.js 16.1.x. 2. Build and start the production server. 3. Open http://localhost:3000 in a browser and keep the tab open. 4. Upgrade Next.js to 16.2.x, rebuild, and restart the server (simulating a new deployment). 5. Without refreshing the browser, click the 'About' link. 6. Observe the 500 error: 'The router state header was sent but could not be parsed.'

Fixing Code Block

Edge Case Audit

This hotfix suppresses parsing errors and may mask corrupted or maliciously crafted headers, leading to silent fallback and potentially extra full reloads for affected sessions. It does not preserve client-side router state for legacy clients, so those users will experience full page navigations after a deployment. The console.warn can be noisy under high traffic. In serverless or concurrent request handling, ensure the fallback path does not write response headers after they have been sent. Rollback suggestion: if this change causes unexpected full navigations or log flooding, revert the try/catch and instead implement a version-aware header parser that can decode both formats.

Ecosystem Topology