Cache Handler Vulnerability in Next.js by Vercel
CVE-2026-103004

6.3MEDIUM

Key Information:

Vendor

Vercel

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103004?

Next.js versions 16.3.0 to 16.3.7 contain a vulnerability that can lead to unintended data exposure through improperly keyed cache entries. Specifically, when cache components are enabled, the use cache function may fail to include root parameters in cache keys for nested calls. As a result, responses meant for one root parameter could inadvertently serve content associated with another. This issue can affect pages rendered both at build time and dynamically and is exacerbated by shared cache headers, allowing further redistribution of erroneously served content. This vulnerability has been addressed in version 16.3.8.

Affected Version(s)

next.js < 16.3.8

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.