ZERO
Back
vulnerabilityCVE-2026-94543

CVE-2026-94543

A flaw was found in Next.js. In self-hosted applications using the Pages Router with static generation or Incremental Static Regeneration (ISR), response cache entries are not sufficiently bound to their source route. A remote attacker can exploit this issue by sending crafted requests to replace a page's cache entry with content from a different route. This results in response cache poisoning, causing the application to serve incorrect content to subsequent visitors.

Exploitation evidence
None confirmed

Affected software

CVSS (Common Vulnerability Scoring System)

Preferred assessment

Vector

Attack vector

Attack complexity

Privileges required

User interaction

Scope

Confidentiality impact

Integrity impact

Availability impact

Source assessments

EPSS (Exploit Prediction Scoring System)

Probability

Percentile

Model

Preferred remediation

Action