Next.js 是一个用于构建全栈 Web 应用的 React 框架。在版本 15.0.0 至 15.5.26 以及 16.3.7 及以下版本中,如果应用包含根层级的通配符页面(catch-all page),并采用了静态生成(Static Generation)或增量静态再生(Incremental Static Regeneration, ISR)的路由策略,则可能使用一个作用域不够严格的共享响应缓存键。攻击者可通过构造单个未认证的请求对该缓存进行投毒(cache poisoning),从而导致跨用户的内容替换
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94483 | 8.3 HIGH | Next.js: Server-Side Request Forgery in Image Optimization |
| CVE-2026-94485 | 6.3 MEDIUM | Next.js: Information disclosure in Next.js App Router metadata image routes via dynamicPar |
| CVE-2026-94544 | 6.3 MEDIUM | Next.js: Pending `use cache` fill can leak Draft Mode content into regular responses and p |
| CVE-2026-94543 | 6.3 MEDIUM | Next.js: Cache poisoning of SSG and ISR pages in self-hosted Next.js applications |
| CVE-2026-94486 | 2.3 LOW | Next.js: Information disclosure in the Next.js development server's Model Context Protocol |
No comments yet