Nextjs, Pages Router Cache Poisoning, CVE-2026-94543 (Moderate) -DC-Oct2026-2837

Listen to this Post

Self-hosted Next.js applications utilizing the Pages Router with Statically Generated (SSG) or Incrementally Regenerated (ISR) pages are susceptible to cache poisoning. The vulnerability stems from the framework’s internal caching mechanism failing to adequately bind a response cache entry to its specific source route. Consequently, an attacker can dispatch a crafted HTTP request that replaces an intended page’s cache entry with content belonging to a completely different route. This misassociation causes the affected web server to serve incorrect, mixed, or malicious content to every subsequent visitor landing on that route. The poisoned state persists indefinitely in the application’s cache storage layer until an explicit cache revalidation or purge occurs. Because this flaw relies on route-keying logic discrepancies rather than memory corruption, it impacts data integrity across shared hosting setups and standalone servers. Crucially, applications deployed on the managed Vercel platform incorporate platform-level isolation and are unaffected by this specific defect. Remediation requires upgrading the affected Next.js packages to the newly secured versions provided in the vendor security advisory.

DailyCVE Form:

Platform: Next.js
Version: 15.0.0-15.5.26, 16.0.0-16.3.7
Vulnerability : Cache Poisoning
Severity: Moderate
date: Sep 30, 2026

Prediction: September 30, 2026

What Undercode Say

The caching layer fails to tie entries to source routes.
Attackers replace valid page contents with cross-route data payloads.
Self-hosted infrastructures bear full exposure risks while Vercel remains safe.

Exploit: (Educational Purposes!)

curl -H "X-Forwarded-Host: attacker-controlled-target" "http://self-hosted-nextjs-app/target-route"

Protection: from this CVE

Upgrade package versions immediately.

Apply versions 15.5.27 or 16.3.8.

Purge stale cache entries post-patch.

Impact:

Persistent serving of wrong page content.

Complete loss of application integrity.

Broad user-facing misinformation risks.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top