Input validation error in Next.js - CVE-2026-94543

 

Input validation error in Next.js - CVE-2026-94543

Published: October 2, 2026


Vulnerability identifier: #VU153126
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-94543
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause pages to serve incorrect content.

The vulnerability exists due to improper cache entry handling in the Pages Router when processing requests for statically generated or incrementally regenerated pages in self-hosted applications. A remote attacker can send requests that cause a page's cache entry to be replaced with content from a different route to cause pages to serve incorrect content.

Applications deployed on Vercel are not affected.


Affected software

Next.js

How to mitigate CVE-2026-94543

Install security update from vendor's website.

Next.js - addressed in versions 15.5.27, 16.3.8

External References

Related Security Bulletins