FixVibe

// sondes / spotlight

Next.js Header Configuration Drift

Headers set on `/` do not always protect nested routes.

What it is

Next.js makes it easy to add headers in `next.config.js`, but the source pattern decides which routes get them. A rule that protects the homepage can still miss an API route, dashboard path, or nested page.

How it happens

Next.js applies the headers in next.config.js by matching each route against a source pattern. A pattern that covers the homepage can miss nested pages, API routes, or the dashboard, so CSP, HSTS, frame protection, and nosniff quietly disappear on the routes that hold real user data. A leftover `X-Powered-By: Next.js` banner also tells attackers which framework to target.

What an attacker gets

Header drift weakens defense-in-depth exactly where real app behavior lives: dashboards, API routes, and nested pages. Missing CSP leaves XSS with fewer guardrails, missing frame protection invites clickjacking, and framework banners give attackers cleaner fingerprinting.

// what fixvibe reports

What FixVibe reports

Runs in active scans of a domain you have verified you own, on Hobby and above. Each finding shows the affected URL or host, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Set `poweredByHeader: false` and use broad `/:path*` header coverage for site-wide protections, with explicit exceptions only where needed. Verify root, nested, and API routes after deploy.

// lance-le sur ta propre app

Continue de shipper pendant que FixVibe veille.

Verify you own the domain, then run active checks alongside the passive ones.

Sondes actives
138
tests dans cette catégorie
modules
58
vérifications sondes actives dédiées
verified domains
130+
active checks after verification
Verify your domain →

// checks récents · correctifs pratiques · shippe sereinement

Next.js Header Configuration Drift: what it is and how to fix it · FixVibe