This is a follow up to CVE-2026-22030 to address related CSRF flows in unstable RSC code paths.
[!NOTE] This only affects your application if you are using the unstable RSC APIs
{
"cwe_ids": [
"CWE-352"
],
"github_reviewed": true,
"github_reviewed_at": "2026-07-24T16:44:43Z",
"nvd_published_at": null,
"severity": "HIGH"
}