PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-94543 vercel CVE debrief

Self-hosted Next.js applications using the Pages Router with statically generated (SSG) or incrementally regenerated (ISR) pages are vulnerable to cache poisoning. An attacker can replace a page's cache entry with content from a different route, causing the affected page to serve incorrect content to all visitors until the entry is revalidated. Applications deployed on Vercel are not affected.

Vendor
vercel
Product
next
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for Next.js applications, particularly those using the Pages Router with SSG or ISR pages, should assess exposure and apply patches or mitigations to prevent cache poisoning attacks.

Why it matters

CVE-2026-94543 is a cache poisoning vulnerability in Next.js applications that can cause affected pages to serve incorrect content to visitors. Defenders should assess exposure, apply patches or mitigations, and monitor applications for potential attacks.

  • Defenders must verify affected versions and apply patches or mitigations to prevent cache poisoning.
  • Self-hosted Next.js applications using SSG or ISR pages are at risk of serving incorrect content to visitors.
  • Defenders should monitor applications for potential cache poisoning attacks and review incident response plans.

Technical summary

The vulnerability occurs in self-hosted Next.js applications using the Pages Router with statically generated (SSG) or incrementally regenerated (ISR) pages. An attacker can replace a page's cache entry with content from a different route, causing the affected page to serve incorrect content to all visitors until the entry is revalidated. This can happen because the cache entry for a page can be overwritten with content from a different route, leading to incorrect content being served to visitors. Defenders should prioritize verifying affected versions, assessing exposure, and applying patches or mitigations to prevent cache poisoning attacks.

Defensive priority

Defenders should prioritize verifying affected versions, assessing exposure, and applying patches or mitigations.

Recommended defensive actions

  • Verify if the Next.js application is self-hosted and uses the Pages Router with SSG or ISR pages.
  • Assess exposure by checking if the application is affected by the cache poisoning vulnerability.
  • Apply patches or mitigations, such as upgrading to version 15.5.27 or 16.3.8, or implementing revalidation.
  • Monitor the application for potential cache poisoning attacks.
  • Review and update incident response plans to address potential cache poisoning incidents.

Evidence notes

The source corpus provides details on the vulnerability, affected versions, and patches. However, it does not provide information on exploitation or specific attack vectors. Self-hosted Next.js applications using the Pages Router with statically generated (SSG) or incrementally regenerated (ISR) pages are vulnerable to cache poisoning. Defenders should verify affected versions, assess exposure, and apply patches or mitigations to prevent cache poisoning attacks. The vulnerability occurs because an attacker can replace a page's cache

Sources and references

Verified primary and authoritative sources

  • CVE-2026-94543 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-94543

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-94543 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94543

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Next.js has cache poisoning of SSG and ISR pages in self-hosted applications

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-4jqv-mc3x-m676.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/vercel/next.js/security/advisories/GHSA-4jqv-mc3x-m676

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/vercel/next.js/commit/52c94abdd2ea5f416f5e8353ea8a2edd3fe311b8

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/vercel/next.js/commit/719e4c67d6e92df60246f95e1d96e2dd60789a52

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/vercel/next.js

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/vercel/next.js/releases/tag/v15.5.27

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/vercel/next.js/releases/tag/v16.3.8

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.