Information disclosure in Next.js - CVE-2026-103004
Published: October 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose content generated for a different root parameter value.
The vulnerability exists due to improper cache key generation in nested 'use cache' functions when an inner cached function call is served from an existing cache entry. A remote attacker can request content that reuses an enclosing cache entry to disclose content generated for a different root parameter value.
Cache Components must be enabled. The content served depends on which invocation first wrote the cache entry, and leaked values cannot be attacker-controlled.