Acceptance of Extraneous Untrusted Data With Trusted Data in Next.js - CVE-2026-94484
Published: October 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a persistent denial of service.
The vulnerability exists due to improper cache handling in the shared response cache for SSG/ISR rendering when handling a crafted request in an application that uses a root-level catch-all page with statically generated or incremental static regeneration routes. A remote attacker can send a crafted request to cause a persistent denial of service.