mediumCVSS 5.3Vulnerability

CVE-2026-94543

Self-hosted Next.js applications that use the Pages Router with statically generated (SSG) or incrementally regenerated (ISR) pages can have a page's cache entry replaced with content from a different route, causing the affected page to serve wrong content to every visitor until the entry is revalidated. Applications deployed on Vercel are not affected.

Properties

severity
medium
summary
Next.js has cache poisoning of SSG and ISR pages in self-hosted applications
cvss_score
5.3
retrieved_at
2026-10-07T22:35:46+00:00
ghsa_published
2026-10-07T20:32:06Z
source_url
https://github.com/advisories/GHSA-4jqv-mc3x-m676
ghsa_updated
2026-10-07T20:32:07Z
ghsa_id
GHSA-4jqv-mc3x-m676
last_source
GitHub Advisory Database
cve_id
CVE-2026-94543
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
signal_observed_at
2026-10-07T22:35:46+00:00
is_ghsa_only
false

Related Entities (4)

HAS_WEAKNESS (1)

→[Weakness]Use of Cache Containing Sensitive Information

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]npm/next

AFFECTS (1)

→[Software]npm/next

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-94543 (CVSS 5.3) — Ninja Signal Threat Intelligence | Ninja Signal