OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-103004

MEDIUM · CVSS 5.3 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Next.js versions 16.3.0 to 16.3.7 are vulnerable due to improper caching of `use cache` handlers, which can lead to the leakage of return values across different root parameters. This vulnerability may allow a response for one root parameter to inadvertently serve content intended for another, potentially exposing sensitive information. Developers using affected versions should prioritize upgrading to version 16.3.8 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-103004
Severity
MEDIUM
CVSS
5.3
EPSS
0.25%

Original NVD Description

Next.js versions from 16.3.0 to 16.3.7 warm `use cache` handlers using `next/root-params` and can leak their return value to pages with different root params. With Cache Components enabled (cacheComponents: true), a 'use cache' function that calls another 'use cache' function that reads a root param can be keyed incorrectly when the inner call is served from an existing entry: the enclosing function's cache key then omits that root param. The enclosing entry is written once and reused for all root param values, so a response for one root param value can serve content produced for a different value — whether the page is prerendered at build time or at runtime, or rendered dynamically. Shared cache headers let downstream caches redistribute the content further. What values are leaked cannot be attacker controlled. Which value's content is served depends only on which invocation wrote the entry first. This has been patched in 16.3.8.

Related CVEs

Other vulnerabilities affecting the same vendor(s)