Web Hack List

Preliminary research

Re:CACHE — Excessive reflection, type confusion, and 0-click SXSS on Next.js

AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.

Combines reflected response headers with external caching in a Next.js deployment. Attacker-selected Content-Type makes an RSC response render as HTML when a cache ignores Vary, while a second cached Refresh response directs ordinary navigation to the poisoned content. The chain depends on middleware and cache behavior.

Record

Researcher
Rachid Allam (zhero;) and inzo_
Published by
zhero-web-sec
Date
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Rachid Allam (zhero;) and inzo_, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .