Bug 2477209 (CVE-2026-44576) - CVE-2026-44576 Next.js: Next.js: Cache poisoning vulnerability in React Server Components
Summary: CVE-2026-44576 Next.js: Next.js: Cache poisoning vulnerability in React Serve...
Keywords:
Status: NEW
Alias: CVE-2026-44576
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2482508 2482509 2482514 2482510 2482511 2482512 2482513
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-13 18:02 UTC by OSIDB Bzimport
Modified: 2026-05-28 10:41 UTC (History)
16 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-05-13 18:02:51 UTC
Next.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable to cache poisoning when shared caches do not correctly partition response variants. Under affected conditions, an attacker can cause an RSC response to be served from the original URL and poison shared cache entries so later visitors receive component payloads instead of the expected HTML. This vulnerability is fixed in 15.5.16 and 16.2.5.


Note You need to log in before you can comment on or make changes to this bug.