← Πίσω στην αναζήτηση CVE

CVE-2026-64647

Next.js

Περιγραφή

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. Confidential data in the POST-s response body would then leak to unauthorized requests. Though the request itself will not be deduped. This is only an issue when receiving request bodies with a content type charset other than UTF-8. For example, the UTF-16 byte sequences for 삃삃 and 섄섄 in the request body would share the same cache. This issue has been fixed in versions 15.5.21 and 16.2.11.

CVSS 5.4EPSS 0.33899999999999997%Κίνδυνος 0.56
Προβολή πηγής
Δημοσίευση
2026-07-27 19:17:21
Επηρεαζόμενες εκδόσεις
<=15.5.20,<=16.2.10
Τύπος
Εφαρμογή ιστού
Τελευταία τροποποίηση
2026-07-29 14:38:45
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N