AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Malformed Request URL Causes 500 Response

Next.js router-server fails to handle malformed URL percent-encoding, returning 500 Internal Server Error instead of 400 Bad Request when a catch-all route is present.

highConfidence 92%Next.jsAffected V16.3.0-Canary.35

Origin Analysis

The error handling path for URL decode errors attempts to render a custom 400 page, but that rendering again parses the original malformed URL, throwing a second DecodeError that escapes the outer try/catch, resulting in a 500 response.
1. Create a Next.js app with a catch-all route (e.g., pages/[...slug].js). 2. Build and start the app (npm run build && npm run start). 3. Send a malformed URL request: curl --path-as-is -i 'http://localhost:3000/50%%2050%%' or curl --path-as-is -i 'http://localhost:3000/50%25%2050%25'. 4. Observe 500 Internal Server Error instead of 400.

Fixing Code Block

Edge Case Audit

This patch modifies compiled files in the next dist directory, so it will be overwritten on next update or reinstall. It bypasses any custom 400 error page for malformed URLs, falling back to plain text. Ensure the source TypeScript file (packages/next/src/server/lib/router-server.ts) is patched and rebuilt for a permanent fix. No thread-safety issues expected as the change is local to the request handler. Rollback: remove the added lines to restore original behavior.

Ecosystem Topology