GHSA-3w37-wq28-93x7: Medium severity npm/next vulnerability

Published Oct 7, 2026
·
Updated

Pending use cache fills are shared across requests for the same key without distinguishing Draft Mode requests from regular requests. When two such requests overlap, the second request receives the first request's fill:

- A regular request that overlaps an editor's Draft Mode request receives unpublished content, without any authentication. - A Draft Mode request that overlaps a regular request receives published content instead of the draft.

If the overlapping regular request prerenders a page — for example an on-demand prerender of a route that was not prerendered at build time — the unpublished content can be persisted into the generated page and served to all later visitors of that route until the page is revalidated. Since cached functions can be shared across routes, the poisoned page does not need to be the page the editor is previewing.

Sites are affected if they enable Cache Components (or experimental.useCache) and serve Draft Mode previews whose cached functions return draft-dependent content.

Affected Software

1 affected componentFixes available
npm/next>=16.3.0<16.3.8
16.3.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/next to a version that resolves this vulnerability.

    Fixed in 16.3.8

Event History

Oct 7, 2026
Advisory Published
via GitHub·08:32 PM
Data Sourced
via GitHub·08:32 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are affected?

Sites are affected when they enable Cache Components or experimental.useCache and serve Draft Mode previews whose cached functions return content that depends on draft state. Sites that do not combine these conditions are not identified as affected by the available information.

2

What does exploitation require?

An attacker must cause a regular request to overlap with an editor's Draft Mode request for the same cache key. No authentication is required for the regular request that can receive unpublished content, but the issue depends on timing and user interaction, reflected by the high attack complexity and required user interaction.

3

When can unpublished content persist beyond the overlapping request?

If the overlapping regular request prerenders a page, such as through an on-demand prerender for a route not prerendered at build time, unpublished content can be written into the generated page. That page may then be served to later visitors until it is revalidated, including when the poisoned route differs from the route the editor was previewing.

4

What is the practical mitigation if patching cannot happen immediately?

Avoid using cached functions that return draft-dependent content while serving Draft Mode previews. Disabling Cache Components or experimental.useCache removes one of the stated affected conditions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203