tag
Response-Confusion
CVE-2026-44576
web
MEDIUM 5.4
Next.js RSC Response Cache Poisoning (CVE-2026-44576)
CVE-2026-44576 is a cache poisoning issue in Next.js RSC response handling. In vulnerable versions, RSC and HTML response variants can be mis-partitioned by shared caches when request/response variants are not keyed correctly, allowing attacker-controlled…
Patched
2026-05-17