Intel

AIKIDO-2026-720263

next is vulnerable to Information Disclosure

Information DisclosureCVE-2026-94544 Published 5 days ago

63

Medium Risk

This Affects:

JSnext
16.3.0 - 16.3.7
Fixed in 16.3.8
Are you affected? Scan for Free

TL;DR

With Cache Components or experimental.useCache enabled, next shares an in flight 'use cache' fill across requests that use the same key. A normal request that overlaps a Draft Mode request receives the draft fill, with no authentication check. If that normal request prerenders the page, the unpublished content is stored and sent to later visitors until revalidation. The fix keeps Draft Mode fills separate from normal requests.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you preview drafts with Cache Components or experimental.useCache enabled.

Background info

next is vulnerable to Information Disclosure in versions 16.3.0 - 16.3.7.

How to fix this

Upgrade the next library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform