next: Next.js: Response cache poisoning via improper route binding

cve CVE-2026-94543 2 sources, 2 claims · Watch

Red Hat writes:
next: Next.js: Response cache poisoning via improper route binding the claim
Severity
MEDIUM NVD
moderate Red Hat
CVSS they disagree
5.3 NVD
4.8 Red Hat
Vendor
vercel NVD
Product
next.js NVD
CWE
CWE-524 NVD
CWE-694 Red Hat

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild
  6. Used in ransomware campaigns

Why the CVSS differs

MetricNVDRed Hat
Attack vector AVnetwork Nnetwork N
Attack complexity AClow Lhigh H
Privileges required PRnone Nnone N
User interaction UInone Nnone N
Scope Sunchanged Uunchanged U
Confidentiality Cnone Nnone N
Integrity Inone Nlow L
Availability Alow Llow L

Each source scores the same vulnerability from what it judges the attack to need. The rows marked are where they judge it differently.

Timeline

2026-10-02first spoke of it: Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated or Incremental Static Regeneration pages can key a response cache entry without sufficiently binding it to the source route. A request can replace one page's cache entry with content from a different route, causing the affected page to serve incorrect content to every visitor until revalidation. Applications deployed on Vercel are not affected. This issue is fixed in versions 15.5.27 and 16.3.8.NVD
2026-10-02first spoke of it: next: Next.js: Response cache poisoning via improper route bindingRed Hat

What it is to other things

affectsvercel/next.js
NVD
made_byvercel
NVD

In words only, so not counted until a person confirms one:

affectsvercel/next_js
NVD says “vercel · next.js”
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
CVSS
cvss
conflict
NVD5.3
receipt
Source
NVD
Its words
5.3
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-05 18:25 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-05 18:25 UTC5.3
2026-10-02 18:03 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "next.js",
            "vendor": "vercel",
            "versions": [
              {
                "status": "affected",
                "version": ">= 15.0.0, < 15.5.27"
              },
              {
                "status": "affected",
                "version": ">= 16.0.0, < 16.3.8"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*",
                "matchCriteriaId": "4549C723-DA20-4F91-9332-3E6D2D3D3AE7",
                "versionEndExcluding": "15.5.27",
                "versionStartIncluding": "15.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*",
                "matchCriteriaId": "204D5E98-44FE-4976-BF36-F870F3EFFA5A",
                "versionEndExcluding": "16.3.8",
                "versionStartIncluding": "16.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated or Incremental Static Regeneration pages can key a response cache entry without sufficiently binding it to the source route. A request can replace one page's cache entry with content from a different route, causing the affected page to serve incorrect content to every visitor until revalidation. Applications deployed on Vercel are not affected. This issue is fixed in versions 15.5.27 and 16.3.8."
      }
    ],
    "id": "CVE-2026-94543",
    "lastModified": "2026-10-05T15:01:31.073",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-02T16:16:52.077",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/vercel/next.js/commit/52c94abdd2ea5f416f5e8353ea8a2edd3fe311b8"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/vercel/next.js/commit/719e4c67d6e92df60246f95e1d96e2dd60789a52"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/vercel/next.js/releases/tag/v15.5.27"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/vercel/next.js/releases/tag/v16.3.8"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/vercel/next.js/security/advisories/GHSA-4jqv-mc3x-m676"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-524"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Primary"
      }
    ]
  }
}
—
CVSS
cvss
conflict
Red Hat4.8
receipt
Source
Red Hat
Its words
4.8
Read by
field:cvss3_score
Said since
2026-10-03 00:06 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-94543",
  "CWE": "CWE-694",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2545233",
  "bugzilla_description": "next: Next.js: Response cache poisoning via improper route binding",
  "cvss3_score": "4.8",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-10-02T15:16:49Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-94543.json",
  "severity": "moderate"
}
—
Cvss4
cvss4
NVD6.3
receipt
Source
NVD
Its words
6.3
Read by
field:cve.metrics.cvssMetricV40[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV40[].cvssData.baseScore
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTC6.3
2026-10-02 18:03 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "next.js",
            "vendor": "vercel",
            "versions": [
              {
                "status": "affected",
                "version": ">= 15.0.0, < 15.5.27"
              },
              {
                "status": "affected",
                "version": ">= 16.0.0, < 16.3.8"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*",
                "matchCriteriaId": "4549C723-DA20-4F91-9332-3E6D2D3D3AE7",
                "versionEndExcluding": "15.5.27",
                "versionStartIncluding": "15.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*",
                "matchCriteriaId": "204D5E98-44FE-4976-BF36-F870F3EFFA5A",
                "versionEndExcluding": "16.3.8",
                "versionStartIncluding": "16.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated or Incremental Static Regeneration pages can key a response cache entry without sufficiently binding it to the source route. A request can replace one page's cache entry with content from a different route, causing the affected page to serve incorrect content to every visitor until revalidation. Applications deployed on Vercel are not affected. This issue is fixed in versions 15.5.27 and 16.3.8."
      }
    ],
    "id": "CVE-2026-94543",
    "lastModified": "2026-10-05T15:01:31.073",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-02T16:16:52.077",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/vercel/next.js/commit/52c94abdd2ea5f416f5e8353ea8a2edd3fe311b8"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/vercel/next.js/commit/719e4c67d6e92df60246f95e1d96e2dd60789a52"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/vercel/next.js/releases/tag/v15.5.27"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/vercel/next.js/releases/tag/v16.3.8"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/vercel/next.js/security/advisories/GHSA-4jqv-mc3x-m676"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-524"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Primary"
      }
    ]
  }
}
—
Cvss4 vector
cvss4_vector
NVDCVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
receipt
Source
NVD
Its words
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Read by
field:cve.metrics.cvssMetricV40[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV40[].cvssData.vectorString
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCCVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
2026-10-02 18:03 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "next.js",
            "vendor": "vercel",
            "versions": [
              {
                "status": "affected",
                "version": ">= 15.0.0, < 15.5.27"
              },
              {
                "status": "affected",
                "version": ">= 16.0.0, < 16.3.8"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*",
                "matchCriteriaId": "4549C723-DA20-4F91-9332-3E6D2D3D3AE7",
                "versionEndExcluding": "15.5.27",
                "versionStartIncluding": "15.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*",
                "matchCriteriaId": "204D5E98-44FE-4976-BF36-F870F3EFFA5A",
                "versionEndExcluding": "16.3.8",
                "versionStartIncluding": "16.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated or Incremental Static Regeneration pages can key a response cache entry without sufficiently binding it to the source route. A request can replace one page's cache entry with content from a different route, causing the affected page to serve incorrect content to every visitor until revalidation. Applications deployed on Vercel are not affected. This issue is fixed in versions 15.5.27 and 16.3.8."
      }
    ],
    "id": "CVE-2026-94543",
    "lastModified": "2026-10-05T15:01:31.073",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-02T16:16:52.077",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/vercel/next.js/commit/52c94abdd2ea5f416f5e8353ea8a2edd3fe311b8"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/vercel/next.js/commit/719e4c67d6e92df60246f95e1d96e2dd60789a52"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/vercel/next.js/releases/tag/v15.5.27"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/vercel/next.js/releases/tag/v16.3.8"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/vercel/next.js/security/advisories/GHSA-4jqv-mc3x-m676"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-524"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Primary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
not compared
NVDCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
receipt
Source
NVD
Its words
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV31[].cvssData.vectorString
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
2026-10-02 18:03 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "next.js",
            "vendor": "vercel",
            "versions": [
              {
                "status": "affected",
                "version": ">= 15.0.0, < 15.5.27"
              },
              {
                "status": "affected",
                "version": ">= 16.0.0, < 16.3.8"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*",
                "matchCriteriaId": "4549C723-DA20-4F91-9332-3E6D2D3D3AE7",
                "versionEndExcluding": "15.5.27",
                "versionStartIncluding": "15.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*",
                "matchCriteriaId": "204D5E98-44FE-4976-BF36-F870F3EFFA5A",
                "versionEndExcluding": "16.3.8",
                "versionStartIncluding": "16.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated or Incremental Static Regeneration pages can key a response cache entry without sufficiently binding it to the source route. A request can replace one page's cache entry with content from a different route, causing the affected page to serve incorrect content to every visitor until revalidation. Applications deployed on Vercel are not affected. This issue is fixed in versions 15.5.27 and 16.3.8."
      }
    ],
    "id": "CVE-2026-94543",
    "lastModified": "2026-10-05T15:01:31.073",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-02T16:16:52.077",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/vercel/next.js/commit/52c94abdd2ea5f416f5e8353ea8a2edd3fe311b8"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/vercel/next.js/commit/719e4c67d6e92df60246f95e1d96e2dd60789a52"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/vercel/next.js/releases/tag/v15.5.27"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/vercel/next.js/releases/tag/v16.3.8"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/vercel/next.js/security/advisories/GHSA-4jqv-mc3x-m676"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-524"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Primary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
not compared
Red HatCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
receipt
Source
Red Hat
Its words
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
Read by
field:cvss3_scoring_vector
Said since
2026-10-06 13:01 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
2026-10-06 13:01 UTCCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
2026-10-03 00:06 UTC—
What the source handed over
{
  "CVE": "CVE-2026-94543",
  "CWE": "CWE-694",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2545233",
  "bugzilla_description": "next: Next.js: Response cache poisoning via improper route binding",
  "cvss3_score": "4.8",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-10-02T15:16:49Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-94543.json",
  "severity": "moderate"
}
—
CWE
cwe
different words
NVDCWE-524
receipt
Source
NVD
Its words
CWE-524
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCCWE-524
2026-10-02 18:03 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "next.js",
            "vendor": "vercel",
            "versions": [
              {
                "status": "affected",
                "version": ">= 15.0.0, < 15.5.27"
              },
              {
                "status": "affected",
                "version": ">= 16.0.0, < 16.3.8"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*",
                "matchCriteriaId": "4549C723-DA20-4F91-9332-3E6D2D3D3AE7",
                "versionEndExcluding": "15.5.27",
                "versionStartIncluding": "15.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*",
                "matchCriteriaId": "204D5E98-44FE-4976-BF36-F870F3EFFA5A",
                "versionEndExcluding": "16.3.8",
                "versionStartIncluding": "16.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated or Incremental Static Regeneration pages can key a response cache entry without sufficiently binding it to the source route. A request can replace one page's cache entry with content from a different route, causing the affected page to serve incorrect content to every visitor until revalidation. Applications deployed on Vercel are not affected. This issue is fixed in versions 15.5.27 and 16.3.8."
      }
    ],
    "id": "CVE-2026-94543",
    "lastModified": "2026-10-05T15:01:31.073",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-02T16:16:52.077",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/vercel/next.js/commit/52c94abdd2ea5f416f5e8353ea8a2edd3fe311b8"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/vercel/next.js/commit/719e4c67d6e92df60246f95e1d96e2dd60789a52"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/vercel/next.js/releases/tag/v15.5.27"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/vercel/next.js/releases/tag/v16.3.8"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/vercel/next.js/security/advisories/GHSA-4jqv-mc3x-m676"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-524"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Primary"
      }
    ]
  }
}
—
CWE
cwe
different words
Red HatCWE-694
receipt
Source
Red Hat
Its words
CWE-694
Read by
field:CWE
Said since
2026-10-03 00:06 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-94543",
  "CWE": "CWE-694",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2545233",
  "bugzilla_description": "next: Next.js: Response cache poisoning via improper route binding",
  "cvss3_score": "4.8",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-10-02T15:16:49Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-94543.json",
  "severity": "moderate"
}
—
Product
product
NVDnext.js
receipt
Source
NVD
Its words
next.js
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 18:03 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "next.js",
            "vendor": "vercel",
            "versions": [
              {
                "status": "affected",
                "version": ">= 15.0.0, < 15.5.27"
              },
              {
                "status": "affected",
                "version": ">= 16.0.0, < 16.3.8"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*",
                "matchCriteriaId": "4549C723-DA20-4F91-9332-3E6D2D3D3AE7",
                "versionEndExcluding": "15.5.27",
                "versionStartIncluding": "15.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*",
                "matchCriteriaId": "204D5E98-44FE-4976-BF36-F870F3EFFA5A",
                "versionEndExcluding": "16.3.8",
                "versionStartIncluding": "16.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated or Incremental Static Regeneration pages can key a response cache entry without sufficiently binding it to the source route. A request can replace one page's cache entry with content from a different route, causing the affected page to serve incorrect content to every visitor until revalidation. Applications deployed on Vercel are not affected. This issue is fixed in versions 15.5.27 and 16.3.8."
      }
    ],
    "id": "CVE-2026-94543",
    "lastModified": "2026-10-05T15:01:31.073",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-02T16:16:52.077",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/vercel/next.js/commit/52c94abdd2ea5f416f5e8353ea8a2edd3fe311b8"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/vercel/next.js/commit/719e4c67d6e92df60246f95e1d96e2dd60789a52"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/vercel/next.js/releases/tag/v15.5.27"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/vercel/next.js/releases/tag/v16.3.8"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/vercel/next.js/security/advisories/GHSA-4jqv-mc3x-m676"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-524"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Primary"
      }
    ]
  }
}
—
Severity
severity
NVDMEDIUM
From 4.0 to 6.9.
receipt
Source
NVD
Its words
MEDIUM
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCMEDIUM
2026-10-02 18:03 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "next.js",
            "vendor": "vercel",
            "versions": [
              {
                "status": "affected",
                "version": ">= 15.0.0, < 15.5.27"
              },
              {
                "status": "affected",
                "version": ">= 16.0.0, < 16.3.8"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*",
                "matchCriteriaId": "4549C723-DA20-4F91-9332-3E6D2D3D3AE7",
                "versionEndExcluding": "15.5.27",
                "versionStartIncluding": "15.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*",
                "matchCriteriaId": "204D5E98-44FE-4976-BF36-F870F3EFFA5A",
                "versionEndExcluding": "16.3.8",
                "versionStartIncluding": "16.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated or Incremental Static Regeneration pages can key a response cache entry without sufficiently binding it to the source route. A request can replace one page's cache entry with content from a different route, causing the affected page to serve incorrect content to every visitor until revalidation. Applications deployed on Vercel are not affected. This issue is fixed in versions 15.5.27 and 16.3.8."
      }
    ],
    "id": "CVE-2026-94543",
    "lastModified": "2026-10-05T15:01:31.073",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-02T16:16:52.077",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/vercel/next.js/commit/52c94abdd2ea5f416f5e8353ea8a2edd3fe311b8"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/vercel/next.js/commit/719e4c67d6e92df60246f95e1d96e2dd60789a52"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/vercel/next.js/releases/tag/v15.5.27"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/vercel/next.js/releases/tag/v16.3.8"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/vercel/next.js/security/advisories/GHSA-4jqv-mc3x-m676"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-524"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Primary"
      }
    ]
  }
}
medium
Severity
severity
Red Hatmoderate
A flaw that is harder to exploit, or whose impact is limited.
receipt
Source
Red Hat
Its words
moderate
Read by
field:severity
Said since
2026-10-03 00:06 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-94543",
  "CWE": "CWE-694",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2545233",
  "bugzilla_description": "next: Next.js: Response cache poisoning via improper route binding",
  "cvss3_score": "4.8",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-10-02T15:16:49Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-94543.json",
  "severity": "moderate"
}
medium
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-10-05 18:25 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-05 18:25 UTCAnalyzed
2026-10-02 18:03 UTCAwaiting Analysis
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "next.js",
            "vendor": "vercel",
            "versions": [
              {
                "status": "affected",
                "version": ">= 15.0.0, < 15.5.27"
              },
              {
                "status": "affected",
                "version": ">= 16.0.0, < 16.3.8"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*",
                "matchCriteriaId": "4549C723-DA20-4F91-9332-3E6D2D3D3AE7",
                "versionEndExcluding": "15.5.27",
                "versionStartIncluding": "15.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*",
                "matchCriteriaId": "204D5E98-44FE-4976-BF36-F870F3EFFA5A",
                "versionEndExcluding": "16.3.8",
                "versionStartIncluding": "16.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated or Incremental Static Regeneration pages can key a response cache entry without sufficiently binding it to the source route. A request can replace one page's cache entry with content from a different route, causing the affected page to serve incorrect content to every visitor until revalidation. Applications deployed on Vercel are not affected. This issue is fixed in versions 15.5.27 and 16.3.8."
      }
    ],
    "id": "CVE-2026-94543",
    "lastModified": "2026-10-05T15:01:31.073",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-02T16:16:52.077",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/vercel/next.js/commit/52c94abdd2ea5f416f5e8353ea8a2edd3fe311b8"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/vercel/next.js/commit/719e4c67d6e92df60246f95e1d96e2dd60789a52"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/vercel/next.js/releases/tag/v15.5.27"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/vercel/next.js/releases/tag/v16.3.8"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/vercel/next.js/security/advisories/GHSA-4jqv-mc3x-m676"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-524"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Primary"
      }
    ]
  }
}
—
Vendor
vendor
NVDvercel
receipt
Source
NVD
Its words
vercel
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 18:03 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "next.js",
            "vendor": "vercel",
            "versions": [
              {
                "status": "affected",
                "version": ">= 15.0.0, < 15.5.27"
              },
              {
                "status": "affected",
                "version": ">= 16.0.0, < 16.3.8"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*",
                "matchCriteriaId": "4549C723-DA20-4F91-9332-3E6D2D3D3AE7",
                "versionEndExcluding": "15.5.27",
                "versionStartIncluding": "15.0.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*",
                "matchCriteriaId": "204D5E98-44FE-4976-BF36-F870F3EFFA5A",
                "versionEndExcluding": "16.3.8",
                "versionStartIncluding": "16.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated or Incremental Static Regeneration pages can key a response cache entry without sufficiently binding it to the source route. A request can replace one page's cache entry with content from a different route, causing the affected page to serve incorrect content to every visitor until revalidation. Applications deployed on Vercel are not affected. This issue is fixed in versions 15.5.27 and 16.3.8."
      }
    ],
    "id": "CVE-2026-94543",
    "lastModified": "2026-10-05T15:01:31.073",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "NONE",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-02T16:16:52.077",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/vercel/next.js/commit/52c94abdd2ea5f416f5e8353ea8a2edd3fe311b8"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/vercel/next.js/commit/719e4c67d6e92df60246f95e1d96e2dd60789a52"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/vercel/next.js/releases/tag/v15.5.27"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/vercel/next.js/releases/tag/v16.3.8"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/vercel/next.js/security/advisories/GHSA-4jqv-mc3x-m676"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-524"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Primary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

next: Next.js: Response cache poisoning via improper route binding
zetlyn/cve-redhat · 2026-10-02
cvss 4.8 cvss_vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L cwe CWE-694 severity moderate source
Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated or Incremental Static Regeneration pages can key a response cache entry without sufficiently binding it to the source route. A request can replace one page's cache entry with content from a different route, causing the affected page to serve incorrect content to every visitor until revalidation. Applications deployed on Vercel are not affected. This issue is fixed in versions 15.5.27 and 16.3.8.
zetlyn/cve-nvd · 2026-10-02
cvss 5.3 cvss4 6.3 cvss4_vector CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X cvss_vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L cwe CWE-524 product next.js severity MEDIUM status Analyzed vendor vercel source