CVE-2026-103004

CVE-2026-103004 published: Next.js versions from 16.3.0 to 16.3.7 warm `use cache` handlers using `next/root-params` and can leak their return value to pages with different root params. With Cache Components enabled (cacheComponents: true), a 'use cache' function that calls another '...

View full NVD advisory → ← Back to CVE watch