The GitHub Advisory Database published two Next.js security advisories on 7 October 2026. The first, CVE-2026-94484, says an app can have its shared response cache poisoned by one crafted request from an unauthenticated user. The app must have a root-level catch-all page, which answers any web address, plus pages built ahead of time (SSG) or rebuilt on a schedule (ISR). Its title says this can swap content between users and cause a lasting denial of service. The second, CVE-2026-94543, covers self-hosted apps that use the Pages Router with SSG or ISR pages. It says a page's cache entry can be replaced with content from another route, so every visitor gets wrong content until the entry is revalidated.
The second advisory says apps deployed on Vercel are not affected. The first advisory does not say whether Vercel apps are affected. Both link to Next.js releases 15.5.27 and 16.3.8. The text shown does not state that these are the fixes. It also does not list affected versions, give severity ratings, or say whether anyone has used either flaw in attacks.
Both flaws sit in a cache that serves every visitor, so one bad entry reaches all of them. Teams that run Next.js themselves with SSG or ISR pages can check whether their setup matches these descriptions. The linked releases are the place to look for what changed.