mediumCVSS 4.2Vulnerability

CVE-2026-94544

Pending `use cache` fills are shared across requests for the same key without distinguishing Draft Mode requests from regular requests. When two such requests overlap, the second request receives the first request's fill: - A regular request that overlaps an editor's Draft Mode request receives unpublished content, without any authentication. - A Draft Mode request that overlaps a regular request receives published content instead of the draft. If the overlapping regular request prerenders a page — for example an on-demand prerender of a route that was not prerendered at build time — the unpublished content can be persisted into the generated page and served to all later visitors of that route until the page is revalidated. Since cached functions can be shared across routes, the poisoned page does not need to be the page the editor is previewing. Sites are affected if they enable Cache Components (or `experimental.useCache`) and serve Draft Mode previews whose cached functions return draft-dependent content.

Properties

severity
medium
summary
Next.js: Pending `use cache` fill can leak Draft Mode content into regular responses and persisted pages
cvss_score
4.2
retrieved_at
2026-10-07T22:35:46+00:00
ghsa_published
2026-10-07T20:32:13Z
source_url
https://github.com/advisories/GHSA-3w37-wq28-93x7
ghsa_updated
2026-10-07T20:32:15Z
ghsa_id
GHSA-3w37-wq28-93x7
last_source
GitHub Advisory Database
cve_id
CVE-2026-94544
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
signal_observed_at
2026-10-07T22:35:46+00:00
is_ghsa_only
false

Related Entities (4)

HAS_WEAKNESS (1)

→[Weakness]Use of Cache Containing Sensitive Information

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]npm/next

AFFECTS (1)

→[Software]npm/next

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-94544 (CVSS 4.2) — Ninja Signal Threat Intelligence | Ninja Signal