Vulnerability GHSA-4jqv-mc3x-m676

Medium Risk
MEDIUM RISK
CVSS Score: 5.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
7 hours ago
October 07, 2026 at 08:32 PM UTC
Next.js has cache poisoning of SSG and ISR pages in self-hosted applications
15.0.0 - 15.5.26 and 16.0.0 - 16.3.7
15.0.0 - 15.5.26 and 16.0.0 - 16.3.7

Summary

Next.js has cache poisoning of SSG and ISR pages in self-hosted applications

Details

Self-hosted Next.js applications that use the Pages Router with statically generated (SSG) or incrementally regenerated (ISR) pages can have a page's cache entry replaced with content from a different route, causing the affected page to serve wrong content to every visitor until the entry is revalidated. Applications deployed on Vercel are not affected.

Impacted packages

Timeline

Published
7 hours ago
October 07, 2026 at 08:32 PM UTC
Fixed (15.5.27)
Unknown
Unknown
Fixed (16.3.8)
Unknown
Unknown
Last Modified
7 hours ago
October 07, 2026 at 08:45 PM UTC