CVE WATCH / VULNERABILITY DETAIL
CVE-2026-103004
UNKNOWNCVSS 0NVD feed
Published 1 October 2026 · tracked since 2 October 2026
Description
Next.js versions from 16.3.0 to 16.3.7 warm `use cache` handlers using `next/root-params` and can leak their return value to pages with different root params. With Cache Components enabled (cacheComponents: true), a 'use cache' function that calls another 'use cache' function that reads a root param
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-103921 HIGH 7.4
- CVE-2026-101888 HIGH 7.2
- CVE-2026-101889 MEDIUM 6.5
- CVE-2026-101890 MEDIUM 5.4
- CVE-2026-94620
- CVE-2026-46729 HIGH 7.5
- CVE-2026-47360 HIGH 7.5
- CVE-2026-42356 LOW 3.7
- CVE-2026-42528 MEDIUM 4.3
- CVE-2026-103690 MEDIUM 6.3