tag
Weak-Hash
CVE-2026-44582
web
LOW 3.7
Next.js RSC Cache-Busting Weak Hash Collision (CVE-2026-44582)
Next.js used a weak cache-busting hash for the rsc query parameter in vulnerable versions. Because this hash had practical collision resistance limits, an attacker could generate alternative header/state tuples that map to the same rsc token as a victim route…
Patched
2026-05-17