Page Cache Vulnerability in Next.js Framework by Vercel
CVE-2026-94543
What is CVE-2026-94543?
Next.js, a popular framework for building React applications, has a vulnerability affecting versions from 15.0.0 to 15.5.27 and 16.3.8. This vulnerability arises in self-hosted applications using the Pages Router with statically generated or Incremental Static Regeneration pages. An attacker can exploit this issue by manipulating cache entries, allowing a request to replace one page's cache entry with content from another route. As a result, users may experience incorrect content delivered on affected pages until the cache is revalidated. It is essential for users of these versions to update to the latest releases (15.5.27 and 16.3.8) to mitigate this risk.
Affected Version(s)
next.js >= 15.0.0, < 15.5.27 < 15.0.0, 15.5.27
next.js >= 16.0.0, < 16.3.8 < 16.0.0, 16.3.8