Intel

AIKIDO-2026-465540

next is vulnerable to Information Disclosure

Information DisclosureCVE-2026-103004 Published 5 days ago

63

Medium Risk

This Affects:

JSnext
16.3.0 - 16.3.7
Fixed in 16.3.8
Are you affected? Scan for Free

TL;DR

With Cache Components enabled, a 'use cache' function in next that calls another 'use cache' function reading a root param can omit that param from its own cache key. The outer entry is written once, by whichever request arrives first, and then reused for every root param value. Content produced for one value can be sent for another, including from prerendered pages and downstream caches. The fix includes the root param in the outer cache key.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you enable Cache Components with nested 'use cache' functions that read a root param.

Background info

next is vulnerable to Information Disclosure in versions 16.3.0 - 16.3.7.

How to fix this

Upgrade the next library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform