Next.js applications that use a root-level catch-all page together with statically generated or Incremental Static Regeneration routes can have their shared response cache poisoned by a single unauthenticated crafted request.
{
"cwe_ids": [
"CWE-524"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T20:31:13Z",
"nvd_published_at": "2026-10-02T16:16:51Z",
"severity": "MODERATE"
}