tag
Header-Smuggling
CVE-2026-44572
web
LOW 3.1
Next.js x-nextjs-data Cache Poisoning (CVE-2026-44572)
CVE-2026-44572 is a cache poisoning vulnerability in Next.js Pages Router redirect handling. Pre-patch, any external client could set the internal x-nextjs-data: 1 header on a request to a redirecting URL, causing the server to return a 200 OK with…
Patched
2026-05-17