Next.js 是一个用于构建全栈 Web 应用的 React 框架。在版本 16.3.0 至 16.3.8 之间,针对相同键(key)的 挂起填充(pending fill)会被共享,但未将“草稿模式”(Draft Mode)请求与普通请求分离开来。这可能导致以下两种情况: 1. 一个重叠的普通请求可能接收到由编辑器的“草稿模式”填充提供的、未经身份验证的未发布内容; 2. 一个重叠的“草稿模式”请求可能接收到由普通请求填充提供的已发布内容。 当普通请求对页面进行预渲染时,依赖于草稿状态的内容可能会残留在生成的页
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94483 | 8.3 HIGH | Next.js: Server-Side Request Forgery in Image Optimization |
| CVE-2026-94484 | 6.3 MEDIUM | Next.js: Cache poisoning in Next.js SSG/ISR rendering leads to cross-user content substitu |
| CVE-2026-94485 | 6.3 MEDIUM | Next.js: Information disclosure in Next.js App Router metadata image routes via dynamicPar |
| CVE-2026-94543 | 6.3 MEDIUM | Next.js: Cache poisoning of SSG and ISR pages in self-hosted Next.js applications |
| CVE-2026-94486 | 2.3 LOW | Next.js: Information disclosure in the Next.js development server's Model Context Protocol |
No comments yet