CVE-2026-94544Medium· 6.3▾ SunlitNext.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without separating Draft Mode requests from regular requests. An overlapping regular req…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without separating Draft Mode requests from regular requests. An overlapping regular request can receive unauthenticated unpublished content from an editor's Draft Mode fill, while an overlapping Draft Mode request can receive published content from a regular fill. When the regular request prerenders a page, the draft-dependent content can persist in the generated page and be served to later visitors until revalidation. Sites are affected when Cache Components or experimental.useCache is enabled and cached functions return draft-dependent content. This issue is fixed in version 16.3.8.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-94543Medium· 6.3Next.js is a React framework for building full-stack web applications
CVE-2026-94484Medium· 6.3Next.js is a React framework for building full-stack web applications
CVE-2026-103004Medium· 6.3Next.js versions from 16.3.0 to 16.3.7 warm `use cache` handlers using `next/root-params` and can leak their return value to pages with different root params
CVE-2026-94485Medium· 6.3Next.js is a React framework for building full-stack web applications
CVE-2026-94486Low· 2.3Next.js is a React framework for building full-stack web applications
CVE-2026-94483High· 8.3Next.js is a React framework for building full-stack web applications