AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Invalid URL / Internal Server Error In Response To OPTIONS * Request

Next.js 16.2.0 and later respond with a 500 Internal Server Error when receiving an OPTIONS * request, whereas earlier versions correctly returned 400 Bad Request or another valid response. This regression affects both development and production servers.

highConfidence 75%Next.jsAffected V16.2.0 - 16.4.0-Canary.53

Origin Analysis

In Next.js 16.2.0, changes to the request handling pipeline removed or altered validation for non-path request targets such as '*'. The server assumes req.url starts with '/', causing an unhandled exception during URL parsing or routing for the '*' target, resulting in a 500 response.
1. Start a Next.js app with `npm run dev -- --port 3001`\n2. Run `curl -iw"\n" --http1.1 --request OPTIONS --request-target '*' http://127.0.0.1:3001`\n3. Observe the 500 Internal Server Error response.

Fixing Code Block

Edge Case Audit

This hotfix hardcodes a 400 response for all methods with a '*' target; some legitimate HTTP methods (e.g., OPTIONS *) might expect a 200 or 204 per RFC 7230, so a more nuanced handling could be required. Additionally, if a reverse proxy normalizes '*' to a different value before reaching Next.js, this check may not trigger. Rollback via `git revert <commit-hash>` is recommended if this fix causes unexpected issues with other non-standard request targets.

Ecosystem Topology