Information disclosure in Next.js - CVE-2026-103004

 

Information disclosure in Next.js - CVE-2026-103004

Published: October 2, 2026


Vulnerability identifier: #VU153122
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-103004
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose content generated for a different root parameter value.

The vulnerability exists due to improper cache key generation in nested 'use cache' functions when an inner cached function call is served from an existing cache entry. A remote attacker can request content that reuses an enclosing cache entry to disclose content generated for a different root parameter value.

Cache Components must be enabled. The content served depends on which invocation first wrote the cache entry, and leaked values cannot be attacker-controlled.


Affected software

Next.js

How to mitigate CVE-2026-103004

Install security update from vendor's website.

Next.js - update to 16.3.8

External References

Related Security Bulletins