Intel

AIKIDO-2026-10752

next is vulnerable to Cache Poisoning

Cache PoisoningCVE-2026-44582 Published May 7, 2026

37

Low Risk

This Affects:

JSnext
13.4.6 - 15.5.15
Fixed in 15.5.16
16.0.0 - 16.2.4
Fixed in 16.2.5
Are you affected? Scan for Free

TL;DR

RSC cache-busting values can collide in practical deployment conditions that use shared caches. Collisions let attackers poison cache variants so users receive incorrect component responses for a URL. The weakness is insufficient collision resistance in response variant separation. The fix strengthens cache-busting generation to reduce practical collisions and improve variant isolation.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

next is vulnerable to Cache Poisoning in versions 13.4.6 - 15.5.15 and 16.0.0 - 16.2.4.

How to fix this

Upgrade the next library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform