ZERO
Back
vulnerabilityCVE-2026-94544

CVE-2026-94544

A flaw was found in Next.js. Pending cache operations do not properly separate Draft Mode requests from standard requests when fulfilling matching cache keys. Under concurrent request conditions, an unauthenticated user can receive unpublished draft content generated during an editor's session. If this content is prerendered, the draft data may persist in the application cache and be served to subsequent visitors, leading to information disclosure.

Severity
3.7Low
Exploitation evidence
None confirmed

Affected software

CVSS (Common Vulnerability Scoring System)

Preferred assessment

Vector

Attack vector

Attack complexity

Privileges required

User interaction

Scope

Confidentiality impact

Integrity impact

Availability impact

Source assessments

EPSS (Exploit Prediction Scoring System)

Probability

Percentile

Model

Preferred remediation

Action