GHSA-4jqv-mc3x-m676MediumCVSS 5.3

Next.js has cache poisoning of SSG and ISR pages in self-hosted applications

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Self-hosted Next.js applications that use the Pages Router with statically generated (SSG) or incrementally regenerated (ISR) pages can have a page's cache entry replaced with content from a different route, causing the affected page to serve wrong content to every visitor until the entry is revalidated. Applications deployed on Vercel are not affected.

🎯 Affected products2

  • npm/next:>= 15.0.0, < 15.5.27
  • npm/next:>= 16.0.0, < 16.3.8

🔗 References (7)