Nextjs, Cache Poisoning, CVE-2026-94484 (Moderate) -DC-Oct2026-2836

Listen to this Post

Next.js applications that combine a root-level catch-all page configuration alongside statically generated or Incremental Static Regeneration routes suffer from a critical response cache limitation. Specifically, the framework handles shared response caching keys in a way that fails to sufficiently scope them back to the exact source route. An unauthenticated attacker can exploit this design flaw by submitting a specially crafted request that successfully poisons the shared cache entry. Once the cache is corrupted, subsequent visitors to the application are served cross-user substitution content or encounter a persistent denial of service condition. Because the cache keys lack necessary routing specificity, the erroneous payload remains mapped globally until the affected cache entries are forcefully revalidated, manually cleared, or replaced through framework patches.

DailyCVE Form:

Platform: Next.js
Version: 15.0.0-15.5.27, 16.0.0-16.3.8
Vulnerability : Cache Poisoning
Severity: Moderate
date: September 30, 2026

Prediction: September 30, 2026

What Undercode Say

npm install [email protected]
npx next build

Exploit: (Educational Purposes!)

GET /%2Findex HTTP/1.1
Host: vulnerable-app.local
X-Forwarded-Host: attacker-controlled.local

Protection

Upgrade Next.js to version 15.5.27 or 16.3.8 immediately, and manually revalidate or purge affected cache keys to clear poisoned entries.

Impact

Cross-user content substitution, exposure of unauthorized sensitive data, and persistent application denial of service affecting all regular incoming visitors.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top