PatchSiren cyber security CVE debrief
CVE-2026-94485 vercel CVE debrief
CVE-2026-94485 debrief based on the supplied source corpus. The CVE record was published on 2026-10-07T20:31:33.000Z and has not been modified since then. Affected product deployments should be reviewed for exposure, with a focus on Next.js App Router applications built with webpack. The vulnerability allows attackers to request metadata image URLs for dynamic segments that were deliberately excluded from generateStaticParams(). Defenders should assess the potential operational impact, including information disclosure through metadata image routes and possible bypass of intended dynamicParams restrictions.
- Vendor
- vercel
- Product
- next
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Next.js App Router applications built with webpack should assess exposure and prioritize patching and configuration reviews. This includes verifying generateStaticParams() configurations to prevent exploitation and potential information disclosure. Operators, platform administrators, vulnerability management teams, and security teams should review the vulnerability details and take necessary actions to protect their systems.
Why it matters
Defenders should care about CVE-2026-94485 because it involves a potential information disclosure vulnerability in Next.js App Router applications built with webpack. The vulnerability allows attackers to request metadata image URLs for dynamic segments that were deliberately excluded from generateStaticParams(). Defenders responsible for these applications should assess exposure, prioritize patching and configuration reviews, and verify generateStaticParams() configurations to prevent exploitation and potential information disclosure.
- Potential information disclosure through metadata image routes
- Possible bypass of intended dynamicParams restrictions
- Need for verification of generateStaticParams() configurations
- Requirement for patching to prevent exploitation
Technical summary
In Next.js App Router applications built with webpack, metadata image routes such as opengraph-image and twitter-image ignore the dynamicParams route segment option. An attacker can request metadata image URLs for dynamic segments that were deliberately excluded from generateStaticParams(). This vulnerability may lead to potential information disclosure through metadata image routes and possible bypass of intended dynamicParams restrictions. Defenders should prioritize verifying and applying patches for Next.js App Router applications built with webpack, particularly those with dynamic segments excluded from generateStaticParams().
Defensive priority
Defenders should prioritize verifying and applying patches for Next.js App Router applications built with webpack, particularly those with dynamic segments excluded from generateStaticParams().
Recommended defensive actions
- Verify and apply patches for Next.js App Router applications built with webpack
- Review and update generateStaticParams() configurations to prevent dynamic segment exposure
- Monitor metadata image routes for suspicious requests
- Perform a thorough review of affected product deployments to identify potential exposure
- Implement compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions and retest remediated assets to ensure successful patching
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The source corpus provides limited information about affected versions and remediation. Further verification is required to determine the full scope of impacted systems and to confirm vendor-provided patches.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-94485 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-94485
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-94485 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94485
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Next.js has information disclosure in App Router metadata image routes via dynamicParams bypass
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-f87g-xv8r-7p7x.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/vercel/next.js/security/advisories/GHSA-f87g-xv8r-7p7x
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/vercel/next.js/commit/2d9f50a409312696145b82b3157aadb6b1fef476
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/vercel/next.js
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/vercel/next.js/releases/tag/v16.3.8
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.