Next.js: Cache poisoning in React Server Component responses
Published May 13, 2026
5.4
MEDIUMCVSS 3.1
EPSS 0.30%
Description
Next.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable to cache poisoning when shared caches do not correctly partition response variants. Under affected conditions, an attacker can cause an RSC response to be served from the original URL and poison shared cache entries so later visitors receive component payloads instead of the expected HTML. This vulnerability is fixed in 15.5.16 and 16.2.5.
Affected products
-
- Version >= 14.2.0, < 15.5.16StatusaffectedConstraints-
- Version >= 16.0.0, < 16.2.5StatusaffectedConstraints-
- Version
No data.
Red Hat Enterprise Linux 10
firefox
Fix deferred
Red Hat Enterprise Linux 10
thunderbird
Fix deferred
Red Hat Enterprise Linux 7
firefox
Fix deferred
Red Hat Enterprise Linux 8
firefox
Fix deferred
Red Hat Enterprise Linux 8
thunderbird
Fix deferred
Red Hat Enterprise Linux 9
firefox
Fix deferred
Red Hat Enterprise Linux 9
thunderbird
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-cuda-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-gaudi-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-rocm-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/disk-image-cuda-rhel9
Fix deferred
Red Hat Trusted Artifact Signer
rhtas/rekor-search-ui-rhel9
Fix deferred
streams for Apache Kafka 2
next
Fix deferred
streams for Apache Kafka 3
next
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | firefox | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | thunderbird | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | firefox | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | firefox | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | thunderbird | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | firefox | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | thunderbird | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-cuda-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-gaudi-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-rocm-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/disk-image-cuda-rhel9 | Fix deferred | n/a |
| Red Hat Trusted Artifact Signer | rhtas/rekor-search-ui-rhel9 | Fix deferred | n/a |
| streams for Apache Kafka 2 | next | Fix deferred | n/a |
| streams for Apache Kafka 3 | next | Fix deferred | n/a |
next
npm
Introduced 14.2.0 Fixed 15.5.16next
npm
Introduced 16.0.0 Fixed 16.2.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | next | 14.2.0 | 15.5.16 |
| npm | next | 16.0.0 | 16.2.5 |
Remediation
Red Hat mitigation
To address this cache poisoning vulnerability in Next.js applications utilizing React Server Components, ensure that any shared caching mechanisms are configured to correctly partition responses. This involves defining cache keys that incorporate all relevant request parameters and headers to prevent serving incorrect content from the cache. Review the documentation for your specific caching solution (e.g., CDN, reverse proxy, or application-level cache) to implement robust cache key strategies and variant handling. Improper cache configuration can lead to an attacker poisoning cache entries, affecting subsequent users.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed May 18, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
May–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.30% (0.00304) | 21.04th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.24% (0.00241) | 14.97th | v5 (v2026.06.15) |
| May 14, 2026 | 0.01% (0.00012) | 1.67th | v4 (v2025.03.14) |
References (8)
- https://access.redhat.com/security/cve/CVE-2026-44576 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2477209 Issue Tracking
- https://github.com/advisories/GHSA-wfc6-r584-vfw7 Advisory
- https://github.com/vercel/next.js/releases/tag/v15.5.16
- https://github.com/vercel/next.js/releases/tag/v16.2.5
- https://github.com/vercel/next.js/security/advisories/GHSA-wfc6-r584-vfw7 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-44576
- https://www.cve.org/CVERecord?id=CVE-2026-44576
Change history (0)
No recorded changes yet.