AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Middleware Redirects Drop _Rsc By Causing RSC Header Mismatch And Cache Poisoning Risk

Redirects issued from proxy.ts via NextResponse.redirect lose the `_rsc` query parameter while retaining the RSC request header, leading to an extra 307 validation redirect and potential cache poisoning when a shared cache keys on the URL.

highConfidence 75%Next.jsAffected V16.4.0-Canary.46

Origin Analysis

NextResponse.redirect in middleware does not preserve the `_rsc` query parameter when constructing the Location URL, while the original RSC request header remains. This discrepancy triggers Next.js's internal validateRSCRequestHeaders on the subsequent request, resulting in an unnecessary second 307. Rewrites and next.config redirects already propagate `_rsc`, but middleware redirects lack this logic.
1. Run repro app in dev mode (`npm dev`). 2. Execute `curl -sI -H 'RSC: 1' 'http://localhost:3000/redirect-source?_rsc=abc123'`. 3. Observe the 307 Location header misses `_rsc` while the RSC header remains.

Fixing Code Block

Edge Case Audit

This hotfix only applies to redirects where you use the helper; existing raw `NextResponse.redirect` calls remain affected. If the redirect destination is cross-origin, do not propagate `_rsc` to avoid leaking the RSC identifier. Rolling back the code change is straightforward; no persisted state. Upstream fix may eventually make this helper unnecessary.

Ecosystem Topology