high · CVSS v3 7.5 · CVSS v4 6.3
CVE-2026-94544
CVE-2026-94544 exposes a cache sharing flaw in Next.js 16.3.0‑16.3.8 that allows unauthenticated users to see unpublished draft content or s
Overview
CVE-2026-94544 exposes a cache sharing flaw in Next.js 16.3.0‑16.3.8 that allows unauthenticated users to see unpublished draft content or see published content in draft mode. The vulnerability arises when Cache Components or experimental.useCache are enabled and cached functions return draft‑dependent data. It can lead to accidental disclosure of sensitive content on public sites.
Description
Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without separating Draft Mode requests from regular requests. An overlapping regular request can receive unauthenticated unpublished content from an editor's Draft Mode fill, while an overlapping Draft Mode request can receive published content from a regular fill. When the regular request prerenders a page, the draft-dependent content can persist in the generated page and be served to later visitors until revalidation. Sites are affected when Cache Components or experimental.useCache is enabled and cached functions return draft-dependent content. This issue is fixed in version 16.3.8.
Impact
Confidentiality is compromised as unpublished editor drafts can leak to the public. Integrity is affected because the content served may not reflect the intended published state. Site owners, developers, and end users are impacted by potential data exposure and incorrect content delivery.
Remediation
Upgrade Next.js to version 16.3.8 or later. If an upgrade is not immediately possible, disable Cache Components or experimental.useCache for routes that render draft‑dependent content, or ensure cached functions never return draft data. After changes, purge the cache and trigger a revalidation to remove stale draft content from served pages.
Risk context
The vulnerability has a high severity rating (CVSS v3 7.5) and is not mitigated by any EPSS data, indicating a significant risk that should be addressed promptly.
Affected products
- Next.js 16.3.0-16.3.8
Scores
- Severity
- high
- CVSS v2
- 5
- CVSS v3
- 7.5
- CVSS v4
- 6.3
- EPSS
- —