CVE-2026-94544
Received Received - Intake

Next.js Cache Component Draft Mode Content Exposure

Vulnerability report for CVE-2026-94544, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: GitHub, Inc.

Description

Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without separating Draft Mode requests from regular requests. An overlapping regular request can receive unauthenticated unpublished content from an editor's Draft Mode fill, while an overlapping Draft Mode request can receive published content from a regular fill. When the regular request prerenders a page, the draft-dependent content can persist in the generated page and be served to later visitors until revalidation. Sites are affected when Cache Components or experimental.useCache is enabled and cached functions return draft-dependent content. This issue is fixed in version 16.3.8.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
vercel next.js to 16.3.8 (inc)
vercel next.js to 16.3.0 (exc)
vercel next.js From 16.3.8 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-524 The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Next.js (versions 16.3.0 to 16.3.8) involves improper isolation between Draft Mode requests and regular requests in the cache system. When using the 'use cache' feature, pending cache fills for the same key are shared without separation. This allows a regular request to receive unpublished draft content from an editor's Draft Mode fill, or a Draft Mode request to receive published content from a regular fill. The issue persists until cache revalidation.

Impact Analysis

If you use Next.js with Cache Components or experimental.useCache enabled and serve Draft Mode previews, unpublished content could be exposed to unauthorized users. Regular visitors might see draft-dependent content that should only be visible to editors. In severe cases, unpublished content could be permanently stored in prerendered pages and served to all visitors until the page is revalidated.

Compliance Impact

This vulnerability could lead to unauthorized access to unpublished or sensitive content, potentially violating data protection regulations like GDPR (which requires protection of personal data) and HIPAA (which mandates safeguards for protected health information). Exposure of unpublished drafts may constitute a confidentiality breach.

Mitigation Strategies

Upgrade Next.js to version 16.3.8 or later to apply the security fix addressing the draft mode data leak through cross-request cache sharing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94544. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart