Nextjs, Information Disclosure, CVE-2026-94485 (Medium) -DC-Oct2026-2844

Listen to this Post

In Next.js App Router applications built with webpack, metadata image routes such as opengraph-image and twitter-image ignore the dynamicParams route segment option. An attacker can request metadata image URLs for dynamic segments that were deliberately excluded from generateStaticParams(). This flaw allows unauthorized access to dynamic route contents that were expected to remain hidden or ungenerated. Specifically, when applications utilize webpack configurations alongside static generation restrictions, the routing logic fails to properly evaluate dynamicParams boundaries for image generation handlers. Consequently, malicious actors can systematically probe and retrieve sensitive information or media assets associated with restricted segments. The vulnerability compromises the data isolation guarantees intended by developers who explicitly configured exclusion parameters for their dynamic routing segments. Exploitation relies entirely on targeting these specific metadata image endpoints directly via crafted HTTP requests. Vercel addressed this issue in security updates by ensuring dynamicParams restrictions are correctly enforced across all metadata image routes during webpack compilations.

DailyCVE Form:

Platform: Next.js
Version: 16.0.0-16.3.7
Vulnerability : Information Disclosure
Severity : Medium
Date : September 30, 2026

Prediction : September 30, 2026

What Undercode Say

Bash Commands and Codes

npm install [email protected]
npm run build

Exploit: (Educational Purposes!)

curl -I https://vulnerable-site.com/blog/hidden-segment/opengraph-image

Protection:

Upgrade Next.js to version 16.3.8 or later to ensure dynamicParams are properly respected by webpack metadata image routes.

Impact:

Attackers can bypass intended static generation constraints to harvest sensitive content from hidden or unrendered dynamic route metadata segments.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top