Page Cache Vulnerability in Next.js Framework by Vercel
CVE-2026-94543

6.3MEDIUM

Key Information:

Vendor

Vercel

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-94543?

Next.js, a popular framework for building React applications, has a vulnerability affecting versions from 15.0.0 to 15.5.27 and 16.3.8. This vulnerability arises in self-hosted applications using the Pages Router with statically generated or Incremental Static Regeneration pages. An attacker can exploit this issue by manipulating cache entries, allowing a request to replace one page's cache entry with content from another route. As a result, users may experience incorrect content delivered on affected pages until the cache is revalidated. It is essential for users of these versions to update to the latest releases (15.5.27 and 16.3.8) to mitigate this risk.

Affected Version(s)

next.js >= 15.0.0, < 15.5.27 < 15.0.0, 15.5.27

next.js >= 16.0.0, < 16.3.8 < 16.0.0, 16.3.8

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.