The GitHub Advisory Database published a notice on 7 October 2026 about Next.js, a web framework. It covers apps that use the App Router and are built with webpack. Image routes for page metadata, named opengraph-image and twitter-image, do not obey a setting called dynamicParams, the advisory says. So an attacker can ask for images tied to pages the developer left out on purpose. The advisory calls this information disclosure and links CVE-2026-94485.
Normally, generateStaticParams lists the pages a site builds ahead of time. The dynamicParams setting then decides whether other values get served. A developer who excludes a page expects it to stay out of reach. The advisory reports that the image routes skip this control. It gives no severity rating, no affected versions and no detail on what the images could reveal. It does not say whether attackers have used the flaw. It links the Next.js v16.3.8 release page without saying what changed.
Leaving a page off the build list is an access decision, and here one route type did not enforce it. Teams can ask three things. Which dynamic routes do we exclude on purpose? Do their generated images show data about a single record? Do we build with webpack?