PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-94485 vercel CVE debrief

CVE-2026-94485 debrief based on the supplied source corpus. The CVE record was published on 2026-10-07T20:31:33.000Z and has not been modified since then. Affected product deployments should be reviewed for exposure, with a focus on Next.js App Router applications built with webpack. The vulnerability allows attackers to request metadata image URLs for dynamic segments that were deliberately excluded from generateStaticParams(). Defenders should assess the potential operational impact, including information disclosure through metadata image routes and possible bypass of intended dynamicParams restrictions.

Vendor
vercel
Product
next
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for Next.js App Router applications built with webpack should assess exposure and prioritize patching and configuration reviews. This includes verifying generateStaticParams() configurations to prevent exploitation and potential information disclosure. Operators, platform administrators, vulnerability management teams, and security teams should review the vulnerability details and take necessary actions to protect their systems.

Why it matters

Defenders should care about CVE-2026-94485 because it involves a potential information disclosure vulnerability in Next.js App Router applications built with webpack. The vulnerability allows attackers to request metadata image URLs for dynamic segments that were deliberately excluded from generateStaticParams(). Defenders responsible for these applications should assess exposure, prioritize patching and configuration reviews, and verify generateStaticParams() configurations to prevent exploitation and potential information disclosure.

  • Potential information disclosure through metadata image routes
  • Possible bypass of intended dynamicParams restrictions
  • Need for verification of generateStaticParams() configurations
  • Requirement for patching to prevent exploitation

Technical summary

In Next.js App Router applications built with webpack, metadata image routes such as opengraph-image and twitter-image ignore the dynamicParams route segment option. An attacker can request metadata image URLs for dynamic segments that were deliberately excluded from generateStaticParams(). This vulnerability may lead to potential information disclosure through metadata image routes and possible bypass of intended dynamicParams restrictions. Defenders should prioritize verifying and applying patches for Next.js App Router applications built with webpack, particularly those with dynamic segments excluded from generateStaticParams().

Defensive priority

Defenders should prioritize verifying and applying patches for Next.js App Router applications built with webpack, particularly those with dynamic segments excluded from generateStaticParams().

Recommended defensive actions

  • Verify and apply patches for Next.js App Router applications built with webpack
  • Review and update generateStaticParams() configurations to prevent dynamic segment exposure
  • Monitor metadata image routes for suspicious requests
  • Perform a thorough review of affected product deployments to identify potential exposure
  • Implement compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions and retest remediated assets to ensure successful patching
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The source corpus provides limited information about affected versions and remediation. Further verification is required to determine the full scope of impacted systems and to confirm vendor-provided patches.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-94485 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-94485

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-94485 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94485

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.