October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk5 min

React Server Component Cache Poisoning: How to Check and Fix Your Deployment

A shared cache can serve the wrong RSC response variant. Identify your deployed framework and packages, apply the relevant patch, and verify CDN or proxy cache handling.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A shared cache can serve an RSC payload where a visitor expects HTML if it treats different response variants as interchangeable. For a Next.js deployment, the durable fix is to upgrade to a release patched for the specific advisory; until then, make the CDN or reverse proxy partition cache entries correctly by RSC-related request headers, honor the response’s Vary behavior, or disable shared caching for affected responses.

What RSC cache poisoning means

React Server Components (RSC) applications can return different representations depending on the request. A cache-poisoning problem arises when a shared intermediary—such as a CDN or reverse proxy—stores one representation and later serves it to a request that expects another. Next.js has documented an issue in which an RSC payload could be served at a URL where a later visitor expects HTML.

As an Amazon Associate I earn from qualifying purchases.

This is a response-variant and cache-handling problem. It is not the same vulnerability as an attacker executing code on the server, and it is not the same as a denial-of-service flaw. The practical questions are which framework and RSC packages your deployed build uses, whether those exact versions are affected, and whether your intermediary cache handles RSC variants correctly.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Separate the cache issues from RCE and denial of service

Next.js RSC response cache poisoning

Next.js advisory GHSA-wfc6-r584-vfw7 describes an RSC response-cache issue. Its reported severity is CVSS 5.4. The affected and patched releases are specific to that advisory; they do not establish that a deployment is clear of other RSC vulnerabilities.

#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

Distinct cache-busting collision

A separate Next.js advisory, CVE-2026-44582, concerns collisions in the _rsc cache-busting value that could lead to poisoned cache entries under affected conditions. Its reported severity is CVSS 3.7. The advisory describes a strengthened cache-busting mechanism and recommends correct handling of Vary for RSC-related request headers or disabling shared caching for affected responses while an upgrade is pending.

React2Shell and other React disclosures

React’s December 3, 2025 advisory for CVE-2025-55182 describes an unauthenticated remote-code-execution flaw in decoding requests to Server Function endpoints. React warned that an application could be vulnerable even without its own Server Function endpoint if it supports RSC. The advisory rated it CVSS 10.0 and recommended upgrading immediately. This is not cache poisoning.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

React also published later disclosures involving denial of service and source-code exposure. The January 26, 2026 update described additional DoS and source-exposure issues; a July 2026 advisory covered another DoS issue. A fix for one disclosure is not a universal fix for later, separate issues.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to tell whether your deployed application is vulnerable

Use the deployed build and its dependency lockfile—not just a top-level React version or a developer’s local checkout. Downstream frameworks can bundle or depend on the RSC packages differently, so the framework maintainer’s advisory for the deployed framework version is essential.

Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
  1. Identify what is actually deployed. Record the Next.js or other framework version from the production build or deployment artifact. Check the lockfile used to create that build for react-server-dom-webpack, react-server-dom-parcel, or react-server-dom-turbopack, as applicable.
  2. Match each component to its own advisory. Check the current official React and framework security bulletins for the exact deployed versions. React’s initial CVE-2025-55182 advisory named RSC package versions 19.0, 19.1.0, 19.1.1, and 19.2.0 as affected, and identified Next.js, React Router, Waku, Parcel RSC, the Vite RSC plugin, and Redwood SDK among affected frameworks or bundlers.
  3. Check the release line and advisory date. Confirm whether the precise deployed version falls inside an advisory’s affected range and whether the recommended fix is available for that release line. Do not infer safety from an old fixed-version note or from a different framework’s package version.
  4. Verify the running deployment after upgrading. Confirm that the rebuilt artifact and production deployment use the patched version. Then review the CDN or reverse-proxy behavior for the RSC routes and headers described in the relevant advisory.

Next.js versions named in the May 2026 cache advisory

For GHSA-wfc6-r584-vfw7, Next.js lists these affected ranges and minimum fixed releases:

Next.js release range Advisory status Minimum fixed release named
>=14.2.0 <15.5.16 Affected by GHSA-wfc6-r584-vfw7 15.5.16
>=16.0.0 <16.2.5 Affected by GHSA-wfc6-r584-vfw7 16.2.5

These are the advisory-specific minimum fixed releases, not a standing recommendation to stop at those versions. Check the current Next.js security guidance and the latest supported patch release for the branch you deploy. The same caution applies to React package fixes: the initial RCE advisory named 19.0.1, 19.1.2, and 19.2.1 as fixed for that issue; the January 2026 update named 19.0.4, 19.1.5, and 19.2.4 for additional issues; and the July 2026 DoS advisory named 19.0.8, 19.1.9, and 19.2.8. Those figures address separate issue scopes, not a single all-purpose threshold.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do if you cannot upgrade immediately

Temporary cache controls reduce exposure to the named cache behavior, but they do not replace the framework patch. Their effectiveness depends on the actual CDN or reverse-proxy configuration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Partition the cache by the relevant request headers. Ensure the cache key distinguishes the RSC request variants identified by the framework advisory; do not let HTML and RSC representations collapse into the same shared entry.
  • Honor Vary. Confirm that the intermediary respects the response’s Vary header for the RSC-related request headers. A header emitted by the origin is not protective if the cache ignores it.
  • Disable shared caching for affected responses if necessary. If you cannot verify correct variant handling, bypass shared caching for affected App Router and RSC responses until the deployment is patched.
  • Test the intermediary’s behavior. Check the cache configuration and response behavior for both HTML navigation and RSC requests, including whether a response cached for one form can be returned to the other. Avoid treating a successful origin response as proof that the shared cache is configured safely.

Patch, cache controls, and WAFs address different layers

Measure Role What it does not establish
Upgrade to the framework release patched for the advisory Permanent corrective action for the named software issue. That other React, framework, or cache advisories are also fixed.
Correct cache-key partitioning and Vary handling Interim mitigation for shared-cache response-variant confusion. That the application’s vulnerable code has been corrected.
Disable shared caching for affected RSC responses Interim mitigation when safe variant partitioning cannot be assured. That unrelated RSC vulnerabilities are addressed.
WAF rules Additional edge defense against known exploit patterns. That the deployed application is patched or protected from every attack variant.

Vercel’s security bulletins describe WAF rules for known exploit patterns but caution that “WAF rules cannot guarantee protection against all possible variants of an attack.” A WAF or managed-hosting control is therefore an additional layer, not a substitute for updating the software and checking cache behavior.

Deployment checklist

  • Identify the framework and RSC packages in the production build and its lockfile.
  • Check current React and framework advisories against those exact deployed versions.
  • Upgrade to the appropriate patched release for each applicable advisory.
  • Confirm that your CDN or reverse proxy partitions RSC response variants and honors relevant Vary headers.
  • Until the patch is deployed, disable shared caching for affected responses if you cannot verify correct cache behavior.
  • Treat WAF rules as supplemental protection, not proof of remediation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.