rootpwn

high · CVSS v3 7.5 · CVSS v4 6.3

CVE-2026-94544

CVE-2026-94544 exposes a cache sharing flaw in Next.js 16.3.0‑16.3.8 that allows unauthenticated users to see unpublished draft content or s

Overview

CVE-2026-94544 exposes a cache sharing flaw in Next.js 16.3.0‑16.3.8 that allows unauthenticated users to see unpublished draft content or see published content in draft mode. The vulnerability arises when Cache Components or experimental.useCache are enabled and cached functions return draft‑dependent data. It can lead to accidental disclosure of sensitive content on public sites.

Description

Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without separating Draft Mode requests from regular requests. An overlapping regular request can receive unauthenticated unpublished content from an editor's Draft Mode fill, while an overlapping Draft Mode request can receive published content from a regular fill. When the regular request prerenders a page, the draft-dependent content can persist in the generated page and be served to later visitors until revalidation. Sites are affected when Cache Components or experimental.useCache is enabled and cached functions return draft-dependent content. This issue is fixed in version 16.3.8.

Impact

Confidentiality is compromised as unpublished editor drafts can leak to the public. Integrity is affected because the content served may not reflect the intended published state. Site owners, developers, and end users are impacted by potential data exposure and incorrect content delivery.

Remediation

Upgrade Next.js to version 16.3.8 or later. If an upgrade is not immediately possible, disable Cache Components or experimental.useCache for routes that render draft‑dependent content, or ensure cached functions never return draft data. After changes, purge the cache and trigger a revalidation to remove stale draft content from served pages.

Risk context

The vulnerability has a high severity rating (CVSS v3 7.5) and is not mitigated by any EPSS data, indicating a significant risk that should be addressed promptly.

Affected products

  • Next.js 16.3.0-16.3.8

Scores

Severity
high
CVSS v2
5
CVSS v3
7.5
CVSS v4
6.3
EPSS
—

Next.js cache draft-mode content-leak webapp high-severity confidentiality

← All CVEs