Cache Handler Vulnerability in Next.js by Vercel
CVE-2026-103004
6.3MEDIUM
What is CVE-2026-103004?
Next.js versions 16.3.0 to 16.3.7 contain a vulnerability that can lead to unintended data exposure through improperly keyed cache entries. Specifically, when cache components are enabled, the use cache function may fail to include root parameters in cache keys for nested calls. As a result, responses meant for one root parameter could inadvertently serve content associated with another. This issue can affect pages rendered both at build time and dynamically and is exacerbated by shared cache headers, allowing further redistribution of erroneously served content. This vulnerability has been addressed in version 16.3.8.
Affected Version(s)
next.js < 16.3.8