Next.js 是一个用于构建全栈 Web 应用的 React 框架。在版本 15.0.0 至 15.5.26,以及 16.3.7 及更早版本中,如果使用 Pages Router 并采用静态生成或增量静态再生(Incremental Static Regeneration, ISR)机制的自托管应用,可能在缓存响应条目时未能充分将其与原始路由路径绑定。攻击者可以通过构造请求,用来自不同路由的内容替换某个页面的缓存条目,从而导致受影响页面在重新验证之前向所有访问者提供错误的内容。在 Vercel 上部署的应用不受此
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94483 | 8.3 HIGH | Next.js: Server-Side Request Forgery in Image Optimization |
| CVE-2026-94484 | 6.3 MEDIUM | Next.js: Cache poisoning in Next.js SSG/ISR rendering leads to cross-user content substitu |
| CVE-2026-94485 | 6.3 MEDIUM | Next.js: Information disclosure in Next.js App Router metadata image routes via dynamicPar |
| CVE-2026-94544 | 6.3 MEDIUM | Next.js: Pending `use cache` fill can leak Draft Mode content into regular responses and p |
| CVE-2026-94486 | 2.3 LOW | Next.js: Information disclosure in the Next.js development server's Model Context Protocol |
No comments yet