mediumCVSS 4.8Vulnerability

CVE-2026-94484

Next.js applications that use a root-level catch-all page together with statically generated or Incremental Static Regeneration routes can have their shared response cache poisoned by a single unauthenticated crafted request.

Properties

severity
medium
summary
Next.js has cache poisoning in SSG/ISR rendering that leads to cross-user content substitution and persistent denial of service
cvss_score
4.8
retrieved_at
2026-10-07T22:35:46+00:00
ghsa_published
2026-10-07T20:31:13Z
source_url
https://github.com/advisories/GHSA-mcj8-r9mp-w47p
ghsa_updated
2026-10-07T20:31:15Z
ghsa_id
GHSA-mcj8-r9mp-w47p
last_source
GitHub Advisory Database
cve_id
CVE-2026-94484
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
signal_observed_at
2026-10-07T22:35:46+00:00
is_ghsa_only
false

Related Entities (4)

HAS_WEAKNESS (1)

→[Weakness]Use of Cache Containing Sensitive Information

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]npm/next

AFFECTS (1)

→[Software]npm/next

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-94484 (CVSS 4.8) — Ninja Signal Threat Intelligence | Ninja Signal