CVE-2026-44582PoC(vercel / next.js)

LOWCVSS 3.7 · LOW

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for vercel next.js systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Next.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared caches with insufficient response partitioning. In affected conditions, collisions in the _rsc cache-busting value can allow an attacker to poison cache entries so users receive the wrong response variant for a given URL. This vulnerability is fixed in 15.5.16 and 16.2.5.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-328

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • next.js

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 5 signals
  • Peaked 1d ago at 2 mentions (2026-05-10); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
next.js

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-05-08: 1Mentions · 2026-05-09: 1Mentions · 2026-05-10: 2Mentions · 2026-05-11: 1PoC Mentioned / Linked · 2026-05-08: 1PoC Mentioned / Linked · 2026-05-09: 1PoC Mentioned / Linked · 2026-05-10: 2PoC Mentioned / Linked · 2026-05-11: 1Exploit Tool / Code · 2026-05-08: 1Exploit Tool / Code · 2026-05-09: 1Exploit Tool / Code · 2026-05-10: 105-0805-0905-1005-11
Signal classification1 categories
PoC
5100.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-05-081
PoC1
2026-05-091
PoC1
2026-05-102
PoC2
2026-05-111
PoC1
Full discourse5 posts
  • dw1@dwisiswant0
    PoC

    CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572 https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    A GitHub repository hosting Proof‑of‑Concept code for multiple CVEs in Next.js 16.2.4 is referenced, but the text provides no evidence of active exploitation, patches, or detailed technical information.

    4126765045576.6K
    16.0K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    The message announces a GitHub repository containing proof‑of‑concept exploits for a set of CVEs in Next.js v16.2.4, without any claims of active exploitation or mitigation details.

    144220813713.7K
    158.6K followersView on X
  • Psycho 🎭@Psycho10k_
    PoC

    Next.js v16.2.4 Security PoC Collection CVE-2026-23870 CVE-2026-44575 CVE-2026-44579 CVE-2026-44574 CVE-2026-44578 CVE-2026-44573 CVE-2026-44581 CVE-2026-44580 CVE-2026-44577 CVE-2026-44576 CVE-2026-44582 CVE-2026-44572 https://github.com/dwisiswant0/next-16.2.4-pocs via: Pr0xy

    Post summary

    The post shares a GitHub repository containing Proof‑of‑Concept code for multiple CVEs affecting Next.js 16.2.4, but it offers no additional technical or exploitation details.

    08043302.5K
    455 followersView on X
  • termireum@termireum
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    The post announces a GitHub repository housing Proof‑of‑Concept exploits for multiple Next.js v16.2.4 CVEs, with no active exploitation reports, patch info, or detailed technical data provided.

    0101810684
    758 followersView on X
  • Huda Al-Assaf@0x0Huda
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    A GitHub repository hosts a collection of Proof‑of‑Concept demonstrations for multiple Next.js v16.2.4 CVEs, but no evidence of active exploitation, patching, or detailed technical information is provided.

    020543.0K
    727 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvercelnext.js-node.js-

Explore more