Cache Security Flaw in Next.js Framework by Vercel
CVE-2026-94544
6.3MEDIUM
What is CVE-2026-94544?
The Next.js framework, commonly used for developing full-stack web applications, has a vulnerability that affects its caching mechanism. Specifically, from versions 16.3.0 to 16.3.8, the framework improperly handles cache fill requests, allowing unauthorized access to content. In Draft Mode, content meant for internal review can inadvertently be served to users of the site if there are overlapping requests. This issue arises when Cache Components or experimental.useCache feature is enabled, leading to potential exposure of unpublished drafts or regular content. The vulnerability has been addressed in version 16.3.8.
Affected Version(s)
next.js >= 16.3.0, < 16.3.8