Intel

AIKIDO-2026-683913

next is vulnerable to Cache Poisoning

Cache PoisoningCVE-2026-94543 Published 5 days ago

63

Medium Risk

This Affects:

JSnext
15.0.0 - 15.5.26
Fixed in 15.5.27
16.0.0 - 16.3.7
Fixed in 16.3.8
Are you affected? Scan for Free

TL;DR

Self hosted next Pages Router apps store SSG and ISR responses in a shared cache keyed from the /_next/data path. The path match ignores letter case, so a request for another casing of a route can replace the cached page. Later visitors receive that wrong page until the entry is revalidated. The fix matches /_next/data paths with case sensitivity.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you self host the Pages Router with SSG or ISR.

Background info

next is vulnerable to Cache Poisoning in versions 15.0.0 - 15.5.26 and 16.0.0 - 16.3.7.

How to fix this

Upgrade the next library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform