GHSA-4jqv-mc3x-m676MediumCVSS 5.3
Next.js has cache poisoning of SSG and ISR pages in self-hosted applications
🔗 CVE IDs covered (1)
📋 Description
Self-hosted Next.js applications that use the Pages Router with statically generated (SSG) or incrementally regenerated (ISR) pages can have a page's cache entry replaced with content from a different route, causing the affected page to serve wrong content to every visitor until the entry is revalidated. Applications deployed on Vercel are not affected.
🎯 Affected products2
- npm/next:>= 15.0.0, < 15.5.27
- npm/next:>= 16.0.0, < 16.3.8
🔗 References (7)
- https://github.com/vercel/next.js/security/advisories/GHSA-4jqv-mc3x-m676
- https://nvd.nist.gov/vuln/detail/CVE-2026-94543
- https://github.com/vercel/next.js/commit/52c94abdd2ea5f416f5e8353ea8a2edd3fe311b8
- https://github.com/vercel/next.js/commit/719e4c67d6e92df60246f95e1d96e2dd60789a52
- https://github.com/vercel/next.js/releases/tag/v15.5.27
- https://github.com/vercel/next.js/releases/tag/v16.3.8
- https://github.com/advisories/GHSA-4jqv-mc3x-m676