AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Next.Js 16.4 TurbopackSharedRuntime Inlines Bootstrap Scripts Without Nonce In Prerendered Shell, Breaking Hydration Under Nonce CSP

With default experimental.turbopackSharedRuntime enabled and cacheComponents true, the prerendered shell includes inline scripts for chunk bootstrap and performance timing that lack a nonce attribute, causing browser to block them under a strict nonce-based CSP. This prevents client-side hydration and interactivity.

highConfidence 95%Next.jsAffected V16.4.0

Origin Analysis

The inline scripts (from getTurbopackChunkGroupBootstrap and requestAnimationFrame timing) are rendered during static prerendering when the per-request nonce is not yet known, and are cached without a placeholder for later nonce injection. As a result, the cached shell lacks nonce attributes, and the browser blocks execution, breaking the client runtime bootstrap.
1. Clone https://github.com/stperic/next-shared-runtime-nonce-repro 2. npm install && npm run build && npm start 3. Ensure Next.js 16.4.0, Turbopack production build, cacheComponents: true, and a per-request nonce CSP via proxy/middleware (script-src 'self' 'nonce-<random>') 4. Open http://localhost:3000 5. Observe CSP violations for inline scripts without nonce and non-responsive counter button

Fixing Code Block

Edge Case Audit

This workaround disables a performance optimization (shared runtime) and may increase initial script payload or reduce caching efficiency. It should be treated as a temporary mitigation. Re-enable the flag after upgrading to a fixed Next.js version and verify nonce injection works. Keep a build-time check to fail if any inline script without nonce is present to prevent regression.

Ecosystem Topology