GHSA-mcj8-r9mp-w47pMediumCVSS 4.8
Next.js has cache poisoning in SSG/ISR rendering that leads to cross-user content substitution and persistent denial of service
🔗 CVE IDs covered (1)
📋 Description
Next.js applications that use a root-level catch-all page together with statically generated or Incremental Static Regeneration routes can have their shared response cache poisoned by a single unauthenticated crafted request.
🎯 Affected products2
- npm/next:>= 16.0.0, < 16.3.8
- npm/next:>= 15.0.0, < 15.5.27
🔗 References (7)
- https://github.com/vercel/next.js/security/advisories/GHSA-mcj8-r9mp-w47p
- https://nvd.nist.gov/vuln/detail/CVE-2026-94484
- https://github.com/vercel/next.js/commit/52c94abdd2ea5f416f5e8353ea8a2edd3fe311b8
- https://github.com/vercel/next.js/commit/719e4c67d6e92df60246f95e1d96e2dd60789a52
- https://github.com/vercel/next.js/releases/tag/v15.5.27
- https://github.com/vercel/next.js/releases/tag/v16.3.8
- https://github.com/advisories/GHSA-mcj8-r9mp-w47p