CVE-2026-94485
MediumAdvisory
Published 7 Oct 2026In the index since 8 Oct 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.3
- base score, highest
- EPSS
- 0.001
- 3rd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 54
- of 18,053 indexed, latest versions
- Container images
- 51
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Next.js has information disclosure in App Router metadata image routes via dynamicParams bypass
Carried by container images the latest versions of 54 of 18,053 indexed charts deploy, on 51 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| nextnpm | 16.0.3, 16.0.10, 16.1.3, 16.1.6+13 more | 16.3.8 | 51 |
- OSV records
- GHSA-f87g-xv8r-7p7x
Charts affected
54 by stars
Container images carrying it
51 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.