Intel

AIKIDO-2026-884170

next is vulnerable to Cache Poisoning

Cache PoisoningCVE-2026-94484 Published 5 days ago

63

Medium Risk

This Affects:

JSnext
15.0.0 - 15.5.26
Fixed in 15.5.27
16.0.0 - 16.3.7
Fixed in 16.3.8
Are you affected? Scan for Free

TL;DR

The next response cache can store an SSG or ISR result under a key that is not tied to the route that produced it. With a root catch all page, one unauthenticated request can write that shared entry so a different route returns the catch all response. The substituted page stays in place until revalidation, and repeated writes can keep the real page unavailable. The fix keys each cached response to its source route.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use a root catch all route together with SSG or ISR.

Background info

next is vulnerable to Cache Poisoning in versions 15.0.0 - 15.5.26 and 16.0.0 - 16.3.7.

How to fix this

Upgrade the next library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform