CVE-2026-94543 Next.js 响应缓存投毒漏洞
影响攻击者可污染页面缓存,导致所有访客看到错误内容
Next.js 是用于构建全栈 Web 应用的 React 框架。在自托管应用使用 Pages Router 且页面为静态生成或增量静态再生(ISR)时,响应缓存条目的键未与源路由充分绑定。攻击者可通过请求将某页面的缓存条目替换为其他路由的内容,使该页面在重新验证前向所有访客返回错误内容。
影响范围
Next.js 15.0.0 至 15.5.27 之前版本,以及 16.3.8 之前版本;仅影响自托管且使用 Pages Router 的静态生成或 ISR 页面,部署在 Vercel 上的应用不受影响。
漏洞详情
该漏洞属于响应缓存投毒。成因是缓存键未充分绑定源路由,导致不同路由的响应可能写入同一缓存条目。攻击者构造特定请求即可用其他路由的内容覆盖目标页面缓存,从而向所有访问者展示被替换的内容。
利用条件与风险
利用前提是目标为自托管、使用 Pages Router 且启用静态生成或 ISR 的 Next.js 应用。实战中可造成页面内容被篡改、误导访客,属于中危缓存投毒风险。
修复建议
官方已在 15.5.27 和 16.3.8 版本中修复,建议升级至对应修复版本。临时缓解措施暂无公开信息。
Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated or Incremental Static Regeneration pages can key a response cache entry without sufficiently binding it to the source route. A request can replace one page’s cache entry with content from a different route, causing the affected page to serve incorrect content to every visitor until revalidation. Applications deployed on Vercel are not affected. This issue is fixed in versions 15.5.27 and 16.3.8.