GHSA-mcj8-r9mp-w47pMediumCVSS 4.8

Next.js has cache poisoning in SSG/ISR rendering that leads to cross-user content substitution and persistent denial of service

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Next.js applications that use a root-level catch-all page together with statically generated or Incremental Static Regeneration routes can have their shared response cache poisoned by a single unauthenticated crafted request.

🎯 Affected products2

  • npm/next:>= 16.0.0, < 16.3.8
  • npm/next:>= 15.0.0, < 15.5.27

🔗 References (7)