Back

MEDIUM

Next.js: Cache poisoning in React Server Component responses

Published May 13, 2026

Description

Next.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable to cache poisoning when shared caches do not correctly partition response variants. Under affected conditions, an attacker can cause an RSC response to be served from the original URL and poison shared cache entries so later visitors receive component payloads instead of the expected HTML. This vulnerability is fixed in 15.5.16 and 16.2.5.

Affected products

Remediation

Red Hat mitigation

To address this cache poisoning vulnerability in Next.js applications utilizing React Server Components, ensure that any shared caching mechanisms are configured to correctly partition responses. This involves defining cache keys that incorporate all relevant request parameters and headers to prevent serving incorrect content from the cache. Review the documentation for your specific caching solution (e.g., CDN, reverse proxy, or application-level cache) to implement robust cache key strategies and variant handling. Improper cache configuration can lead to an attacker poisoning cache entries, affecting subsequent users.

Metrics

Weaknesses (2)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 13, 2026
Updated May 18, 2026
Reserved May 6, 2026
CISA Vulnrichment
Updated May 18, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 13, 2026
GHSA-WFC6-R584-VFW7