Nextjs, Draft Mode Content Leak, CVE-2026-94544 (Medium) -DC-Oct2026-2853

Listen to this Post

The CVE-2026-94544 vulnerability exists within the Next.js framework.

It specifically affects applications utilizing Cache Components or experimental useCache.
The root cause stems from how pending cache fills are managed.
Next.js shares pending use cache fills across requests for identical cache keys.

The caching mechanism fails to distinguish between requests.

Specifically, Draft Mode preview requests and regular requests share the same cache fill.
When a site editor initiates a Draft Mode preview session, content is fetched.
If a regular public visitor triggers a request for the same cache key concurrently,
the request lifecycles overlap within the server process execution window.
The second concurrent request receives the unauthenticated cache fill from the first.
If the first request was a Draft Mode preview, unpublished draft data is leaked.
Conversely, if a preview request overlaps a regular request, public content is returned.

Furthermore, this race condition creates persistent security implications.

If the overlapping regular request prerenders a page dynamically,
such as an on-demand prerender of an unbuilt route,
the sensitive draft content gets permanently baked into the generated HTML.
Once persisted, this poisoned page is served to all subsequent public visitors.
The contaminated page remains active until manual or automatic cache revalidation occurs.
Because cached functions can be reused globally across multiple application routes,
the poisoned page does not even need to match the previewed route.
An editor previewing a hidden blog draft can accidentally poison a high-traffic landing page.
Attackers can exploit this timing overlap to harvest confidential enterprise material.
The flaw severely compromises the isolation guarantees of server-side rendering pipelines.
It bypasses standard authentication checks by leveraging shared memory cache states.
Self-hosted deployments and specific server environments running persistent processes are vulnerable.
Serverless architectures with isolated request lifecycles mitigate this specific race condition vector.
The vulnerability requires draft-dependent content to be returned by cached functions.
Without proper request context separation in cache keys, state bleeding occurs.
Vercel addressed this flaw by updating cache key generation logic in version 16.3.8.
Proper isolation ensures draft headers are factored into all cache lookups.

DailyCVE Form:

Platform: Next.js framework
Version: 16.3.0 to 16.3.8
Vulnerability: Draft mode leak
Severity: Medium severity level
date: September 30 2026

Prediction: Patched September 30

What Undercode Say:

npm install [email protected]
npx next build
// Ensure cache keys incorporate request-specific context flags

Exploit: (Educational Purposes!)

An attacker or concurrent visitor triggers simultaneous requests where an editor’s Draft Mode request overlaps with a regular public request sharing the same `use cache` key, forcing the server to serve draft data to the public user and poison the persistent cache file.

Protection: from this CVE

Upgrade the Next.js package to version 16.3.8 or higher immediately to ensure proper request context separation in cache keys.

Impact:

Unpublished draft content disclosure, persistent cache poisoning across shared application routes, and unauthorized data leakage to unauthenticated public users.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top