CVE-2026-94484
Received Received - Intake

HTTP Cache Poisoning in Next.js Framework

Vulnerability report for CVE-2026-94484, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: GitHub, Inc.

Description

Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, applications with a root-level catch-all page and statically generated or Incremental Static Regeneration routes can use a shared response cache key that is insufficiently scoped to the source route. A single unauthenticated crafted request can poison that cache, causing cross-user content substitution or persistent denial of service until the poisoned entry is revalidated or replaced. This issue is fixed in versions 15.5.27 and 16.3.8.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
vercel next.js From 15.0.0 (inc) to 15.5.27 (inc)
vercel next.js 16.3.8
vercel next.js 15.5.27

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-524 The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Next.js applications using a root-level catch-all page with statically generated or Incremental Static Regeneration routes. It allows an unauthenticated attacker to poison the shared response cache with a single crafted request, causing cross-user content substitution or persistent denial of service until the cache entry is revalidated or replaced.

Detection Guidance

Detecting this vulnerability requires checking if your Next.js application uses a root-level catch-all page with statically generated or ISR routes. Inspect your application's routing structure and cache behavior. No specific commands are provided in the resources, but monitoring for unexpected cache entries or content substitutions may indicate exploitation.

Impact Analysis

An attacker could inject malicious content into cached responses, leading to users seeing incorrect or harmful data. This could result in data tampering, unauthorized access, or service disruptions affecting multiple users.

Compliance Impact

This vulnerability could lead to unauthorized data exposure or tampering, violating confidentiality and integrity requirements in GDPR and HIPAA. Compliance may be impacted if user data is compromised or altered due to cache poisoning.

Mitigation Strategies
  • Upgrade Next.js to version 15.5.27 or 16.3.8 or later to apply the security fixes addressing cache poisoning.
  • Review and remove root-level catch-all pages if they are not necessary for your application.
  • Monitor cache entries and responses for signs of tampering or unauthorized content substitution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94484. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart