CyberRota Analysis
AI-GeneratedSelf-hosted applications using Next.js versions 15.0.0 to 15.5.27 and 16.3.8 are vulnerable due to improper cache entry binding in the Pages Router, allowing a request to overwrite a page's cache with content from a different route. This can lead to users receiving incorrect content until the cache is revalidated, potentially causing misinformation or data exposure. Developers and organizations utilizing affected versions of Next.js should prioritize upgrading to versions 15.5.27 or 16.3.8 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated or Incremental Static Regeneration pages can key a response cache entry without sufficiently binding it to the source route. A request can replace one page's cache entry with content from a different route, causing the affected page to serve incorrect content to every visitor until revalidation. Applications deployed on Vercel are not affected. This issue is fixed in versions 15.5.27 and 16.3.8.
Related CVEs
Other vulnerabilities affecting the same vendor(s)