Use of cache containing sensitive information in Next.js - CVE-2026-94544
Published: October 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose unpublished content.
The vulnerability exists due to improper cache key separation in pending `use cache` fills when overlapping regular and Draft Mode requests are processed. A remote attacker can issue a regular request that overlaps a Draft Mode request to disclose unpublished content.
Exploitation requires Cache Components or `experimental.useCache` to be enabled and cached functions to return draft-dependent content.