vulnerabilityCVE-2026-94543
CVE-2026-94543
A flaw was found in Next.js. In self-hosted applications using the Pages Router with static generation or Incremental Static Regeneration (ISR), response cache entries are not sufficiently bound to their source route. A remote attacker can exploit this issue by sending crafted requests to replace a page's cache entry with content from a different route. This results in response cache poisoning, causing the application to serve incorrect content to subsequent visitors.
Exploitation evidence
None confirmed
Affected software
| Software | Affected versions | Fixed in | Sources |
|---|---|---|---|
CVSS (Common Vulnerability Scoring System)
Preferred assessment
Vector
Attack vector
Attack complexity
Privileges required
User interaction
Scope
Confidentiality impact
Integrity impact
Availability impact
Source assessments
EPSS (Exploit Prediction Scoring System)
Probability
Percentile
Model
Preferred remediation
Action