AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Unbounded Per-Path ISR Cache Control Growth In Long-Lived Next Start Processes

SharedCacheControls stores cache-control metadata for every ISR path in a static Map without any eviction or bound, causing heap memory to grow without limit in production next start servers that generate many distinct ISR paths.

highConfidence 85%Next.jsAffected V16.4.0-Canary.48Affected V16.4.0-Canary.50

Origin Analysis

The SharedCacheControls class in Next.js uses a process-wide static Map that is written on every IncrementalCache.set() call. This Map has no size limit or eviction mechanism and is not governed by cacheMaxMemorySize, disk cache settings, or custom cache handlers, leading to unbounded memory retention.
1. Create a Next.js App Router route with `export const revalidate = 3600` and `generateStaticParams` returning []. 2. Disable the ordinary in-memory ISR cache by setting `cacheMaxMemorySize: 0` in next.config.ts. 3. Build and start with `NODE_OPTIONS=--expose-gc pnpm start`. 4. Request many distinct paths (e.g., /blog/1, /blog/2, ...) using a script. 5. Force garbage collection via a heap endpoint and observe that heapUsed continues to grow after each batch of new paths and does not decrease after idle time.

Fixing Code Block

Edge Case Audit

Evicting cache-control entries may cause paths that are no longer held in memory to lose their cache-control metadata, increasing revalidation or fallback behavior (related to issue #73382). The maxEntries value of 10000 is arbitrary and may need tuning for high path diversity; too low can increase origin load, too high still consumes memory. Rollback: remove the eviction logic or increase maxEntries. Monitor heap usage and origin requests after deploying this change.

Ecosystem Topology