← Back to CVE search

CVE-2026-64648

Next.js

Description

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. Confidential data in the POST-s response body would then leak to unauthorized requests. Though the request itself will not be deduped. This only applies to fetch calls with a request that has a different init than the one passed to fetch. A safe request would be: fetch(new Request(init), init). An unsafe request would be: fetch(new Request(init), aDifferentInit). This issue has been fixed in versions 15.5.21 and 16.2.11.

CVSS 5.4EPSS 0.336%Risk 0.56
View source
Published
2026-07-27 20:16:40
Affected versions
>=12.0.0,<15.5.21,>=16.0.0,<16.2.11
Type
Web application
Last modified
2026-07-29 14:38:20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N