SB2026100219 - Multiple vulnerabilities in Next.js



SB2026100219 - Multiple vulnerabilities in Next.js

Published: October 2, 2026

Security Bulletin ID SB2026100219
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 7
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 43% Low 57%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 7 vulnerabilities.


1) Information disclosure (CVE-ID: CVE-2026-103004)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose content generated for a different root parameter value.

The vulnerability exists due to improper cache key generation in nested 'use cache' functions when an inner cached function call is served from an existing cache entry. A remote attacker can request content that reuses an enclosing cache entry to disclose content generated for a different root parameter value.

Cache Components must be enabled. The content served depends on which invocation first wrote the cache entry, and leaked values cannot be attacker-controlled.


2) Use of cache containing sensitive information (CVE-ID: CVE-2026-94544)

CWE-ID: CWE-524 - Use of Cache Containing Sensitive Information

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose unpublished content.

The vulnerability exists due to improper cache key separation in pending `use cache` fills when overlapping regular and Draft Mode requests are processed. A remote attacker can issue a regular request that overlaps a Draft Mode request to disclose unpublished content.

Exploitation requires Cache Components or `experimental.useCache` to be enabled and cached functions to return draft-dependent content.


3) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-94483)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform server-side request forgery.

The vulnerability exists due to improper validation of allow-listed remote URLs in Image Optimization when processing an attacker-controlled allow-listed remote URL. A remote attacker can provide an attacker-controlled allow-listed remote URL to perform server-side request forgery.

Only applications with images.remotePatterns configured are affected.


4) Origin validation error (CVE-ID: CVE-2026-94486)

CWE-ID: CWE-346 - Origin Validation Error

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive development data.

The vulnerability exists due to improper origin validation in the Model Context Protocol endpoint when handling requests from websites. A remote attacker can trick the developer into visiting a malicious website to disclose sensitive development data.

Only applications running with the development server are affected; production deployments do not serve this endpoint.


5) Input validation error (CVE-ID: CVE-2026-94543)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause pages to serve incorrect content.

The vulnerability exists due to improper cache entry handling in the Pages Router when processing requests for statically generated or incrementally regenerated pages in self-hosted applications. A remote attacker can send requests that cause a page's cache entry to be replaced with content from a different route to cause pages to serve incorrect content.

Applications deployed on Vercel are not affected.


6) Acceptance of Extraneous Untrusted Data With Trusted Data (CVE-ID: CVE-2026-94484)

CWE-ID: CWE-349 - Acceptance of Extraneous Untrusted Data With Trusted Data

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a persistent denial of service.

The vulnerability exists due to improper cache handling in the shared response cache for SSG/ISR rendering when handling a crafted request in an application that uses a root-level catch-all page with statically generated or incremental static regeneration routes. A remote attacker can send a crafted request to cause a persistent denial of service.


7) Improper access control (CVE-ID: CVE-2026-94485)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in App Router metadata image routes when requesting metadata image URLs for dynamic segments deliberately excluded from generateStaticParams(). A remote attacker can request a metadata image URL for an excluded dynamic segment to disclose sensitive information.

The issue affects applications built with webpack.


Remediation

Install update from vendor's website.