Input validation error in Next.js - CVE-2026-94543
Published: October 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause pages to serve incorrect content.
The vulnerability exists due to improper cache entry handling in the Pages Router when processing requests for statically generated or incrementally regenerated pages in self-hosted applications. A remote attacker can send requests that cause a page's cache entry to be replaced with content from a different route to cause pages to serve incorrect content.
Applications deployed on Vercel are not affected.