<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 15:10:52 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-382375</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-382375</link>
      <description>EUVD-2026-382375</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-382375</guid>
    </item>
    <item>
      <title>fkie_cve-2026-94544</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-94544</link>
      <description>&lt;p&gt;Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without separating Draft Mode requests from regular requests. An overlapping regular request can receive unauthenticated unpublished content from an editor&amp;#39;s Draft Mode fill, while an overlapping Draft Mode request can receive published content from a regular fill. When the regular request prerenders a page, the draft-dependent content can persist in the generated page and be served to later visitors until revalidation. Sites are affected when Cache Components or experimental.useCache is enabled and cached functions return draft-dependent content. This issue is fixed in version 16.3.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without separating Draft Mode requests from regular requests. An overlapping regular request can receive unauthenticated unpublished content from an editor&amp;#39;s Draft Mode fill, while an overlapping Draft Mode request can receive published content from a regular fill. When the regular request prerenders a page, the draft-dependent content can persist in the generated page and be served to later visitors until revalidation. Sites are affected when Cache Components or experimental.useCache is enabled and cached functions return draft-dependent content. This issue is fixed in version 16.3.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-94544</guid>
    </item>
    <item>
      <title>GHSA-3w37-wq28-93x7 — Next.js: Pending `use cache` fill can leak Draft Mode content into regular responses and persisted pages</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3w37-wq28-93x7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: next&lt;/p&gt;
&lt;p&gt;Pending `use cache` fills are shared across requests for the same key without distinguishing Draft Mode requests from regular requests. When two such requests overlap, the second request receives the first request&amp;#39;s fill:&lt;/p&gt;
&lt;p&gt;- A regular request that overlaps an editor&amp;#39;s Draft Mode request receives unpublished content, without any authentication.
- A Draft Mode request that overlaps a regular request receives published content instead of the draft.&lt;/p&gt;
&lt;p&gt;If the overlapping regular request prerenders a page — for example an on-demand prerender of a route that was not prerendered at build time — the unpublished content can be persisted into the generated page and served to all later visitors of that route until the page is revalidated. Since cached functions can be shared across routes, the poisoned page does not need to be the page the editor is previewing.&lt;/p&gt;
&lt;p&gt;Sites are affected if they enable Cache Components (or `experimental.useCache`) and serve Draft Mode previews whose cached functions return draft-dependent content.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: next&lt;/p&gt;
&lt;p&gt;Pending `use cache` fills are shared across requests for the same key without distinguishing Draft Mode requests from regular requests. When two such requests overlap, the second request receives the first request&amp;#39;s fill:&lt;/p&gt;
&lt;p&gt;- A regular request that overlaps an editor&amp;#39;s Draft Mode request receives unpublished content, without any authentication.
- A Draft Mode request that overlaps a regular request receives published content instead of the draft.&lt;/p&gt;
&lt;p&gt;If the overlapping regular request prerenders a page — for example an on-demand prerender of a route that was not prerendered at build time — the unpublished content can be persisted into the generated page and served to all later visitors of that route until the page is revalidated. Since cached functions can be shared across routes, the poisoned page does not need to be the page the editor is previewing.&lt;/p&gt;
&lt;p&gt;Sites are affected if they enable Cache Components (or `experimental.useCache`) and serve Draft Mode previews whose cached functions return draft-dependent content.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3w37-wq28-93x7</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3699 — Vercel Next.js: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3699</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Vercel Next.js ausnutzen, um vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder Denial-of-Service-Zustände auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Vercel Next.js ausnutzen, um vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder Denial-of-Service-Zustände auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3699</guid>
    </item>
  </channel>
</rss>
