CVE-2026-94543
Received Received - Intake

Cache Key Confusion in Next.js Pages Router

Vulnerability report for CVE-2026-94543, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: GitHub, Inc.

Description

Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated or Incremental Static Regeneration pages can key a response cache entry without sufficiently binding it to the source route. A request can replace one page's cache entry with content from a different route, causing the affected page to serve incorrect content to every visitor until revalidation. Applications deployed on Vercel are not affected. This issue is fixed in versions 15.5.27 and 16.3.8.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
vercel next.js From 15.0.0 (inc) to 15.5.27 (inc)
vercel next.js 16.3.8
vercel next.js 15.5.27

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-524 The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects self-hosted Next.js applications using the Pages Router with statically generated or incrementally regenerated pages. It allows an attacker to replace a page's cache entry with content from a different route, causing the affected page to serve incorrect content to all visitors until the cache is revalidated. Applications hosted on Vercel are not impacted.

Impact Analysis

The primary impact is on the availability of the system, as incorrect content may be served to users. Confidentiality and integrity are not directly compromised. The attack requires network access, has high complexity, and does not need privileges or user interaction.

Mitigation Strategies

Upgrade Next.js to version 15.5.27 or 16.3.8 or later to patch the vulnerability. If using self-hosted applications with Pages Router and SSG/ISR pages, verify the cache behavior and ensure no unauthorized content is being served.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94543. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart