← Volver al buscador de CVEs

CVE-2026-64648

Next.js

Descripción

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. Confidential data in the POST-s response body would then leak to unauthorized requests. Though the request itself will not be deduped. This only applies to fetch calls with a request that has a different init than the one passed to fetch. A safe request would be: fetch(new Request(init), init). An unsafe request would be: fetch(new Request(init), aDifferentInit). This issue has been fixed in versions 15.5.21 and 16.2.11.

CVSS 5.4EPSS 0.336%Riesgo 0.56
Ver fuente
Publicación
2026-07-27 20:16:40
Versiones afectadas
>=12.0.0,<15.5.21,>=16.0.0,<16.2.11
Tipo
Aplicación web
Última modificación
2026-07-29 14:38:20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N