AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Turbopack Worker Bootstrap Fails When Query String Is Appended To Worker URL After Fragment

In Next.js 16.3.5 with Turbopack, the web worker bootstrap parses its configuration from the URL hash. In-app browsers like Facebook/Instagram append query parameters (e.g. ?fbclid=abc) after the fragment, making the hash value invalid JSON and causing JSON.parse to throw, preventing worker startup.

highConfidence 90%Next.jsAffected V16.3.5

Origin Analysis

The bootstrap reads `location.hash` starting at `#params=`, decodes it, and passes the result to `JSON.parse`. Any query text appended after the fragment by the environment becomes part of the hash and is not stripped before decoding, corrupting the JSON payload.
1. Clone https://github.com/balint-poly/next-turbopack-worker-hash-params 2. Run `npm install` 3. Run `npm run build` (Next.js 16.3.5 with Turbopack) then `npm start` 4. Open http://localhost:3000/ and observe that the control worker posts 'booted', but the worker created with a URL wrapper that appends `?fbclid=abc` throws `Uncaught SyntaxError: Unexpected non-whitespace character after JSON at position 116`.

Fixing Code Block

Edge Case Audit

This fix assumes the encoded JSON payload never contains a literal `?` or `&`, which holds under the current `encodeURIComponent` implementation. If future bootstrap encodes using a different method or includes unencoded query-like characters inside a JSON string, truncation could corrupt valid config. Test with encoded payloads containing `%3F` and `%26` as well as raw `?`/`&` appended in various orders. For rollback, revert this bootstrap change or upgrade to a patched Next.js version; no data migration is required.

Ecosystem Topology