PatchSiren cyber security CVE debrief
CVE-2026-94543 vercel CVE debrief
Self-hosted Next.js applications using the Pages Router with statically generated (SSG) or incrementally regenerated (ISR) pages are vulnerable to cache poisoning. An attacker can replace a page's cache entry with content from a different route, causing the affected page to serve incorrect content to all visitors until the entry is revalidated. Applications deployed on Vercel are not affected.
- Vendor
- vercel
- Product
- next
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Next.js applications, particularly those using the Pages Router with SSG or ISR pages, should assess exposure and apply patches or mitigations to prevent cache poisoning attacks.
Why it matters
CVE-2026-94543 is a cache poisoning vulnerability in Next.js applications that can cause affected pages to serve incorrect content to visitors. Defenders should assess exposure, apply patches or mitigations, and monitor applications for potential attacks.
- Defenders must verify affected versions and apply patches or mitigations to prevent cache poisoning.
- Self-hosted Next.js applications using SSG or ISR pages are at risk of serving incorrect content to visitors.
- Defenders should monitor applications for potential cache poisoning attacks and review incident response plans.
Technical summary
The vulnerability occurs in self-hosted Next.js applications using the Pages Router with statically generated (SSG) or incrementally regenerated (ISR) pages. An attacker can replace a page's cache entry with content from a different route, causing the affected page to serve incorrect content to all visitors until the entry is revalidated. This can happen because the cache entry for a page can be overwritten with content from a different route, leading to incorrect content being served to visitors. Defenders should prioritize verifying affected versions, assessing exposure, and applying patches or mitigations to prevent cache poisoning attacks.
Defensive priority
Defenders should prioritize verifying affected versions, assessing exposure, and applying patches or mitigations.
Recommended defensive actions
- Verify if the Next.js application is self-hosted and uses the Pages Router with SSG or ISR pages.
- Assess exposure by checking if the application is affected by the cache poisoning vulnerability.
- Apply patches or mitigations, such as upgrading to version 15.5.27 or 16.3.8, or implementing revalidation.
- Monitor the application for potential cache poisoning attacks.
- Review and update incident response plans to address potential cache poisoning incidents.
Evidence notes
The source corpus provides details on the vulnerability, affected versions, and patches. However, it does not provide information on exploitation or specific attack vectors. Self-hosted Next.js applications using the Pages Router with statically generated (SSG) or incrementally regenerated (ISR) pages are vulnerable to cache poisoning. Defenders should verify affected versions, assess exposure, and apply patches or mitigations to prevent cache poisoning attacks. The vulnerability occurs because an attacker can replace a page's cache
Sources and references
Verified primary and authoritative sources
-
CVE-2026-94543 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-94543
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-94543 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94543
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Next.js has cache poisoning of SSG and ISR pages in self-hosted applications
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-4jqv-mc3x-m676.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/vercel/next.js/security/advisories/GHSA-4jqv-mc3x-m676
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/vercel/next.js/commit/52c94abdd2ea5f416f5e8353ea8a2edd3fe311b8
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/vercel/next.js/commit/719e4c67d6e92df60246f95e1d96e2dd60789a52
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/vercel/next.js
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/vercel/next.js/releases/tag/v15.5.27
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/vercel/next.js/releases/tag/v16.3.8
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.