Popis
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. Confidential data in the POST-s response body would then leak to unauthorized requests. Though the request itself will not be deduped. This only applies to fetch calls with a request that has a different init than the one passed to fetch. A safe request would be: fetch(new Request(init), init). An unsafe request would be: fetch(new Request(init), aDifferentInit). This issue has been fixed in versions 15.5.21 and 16.2.11.
CVSS 5.4EPSS 0.336%Riziko 0.56
Zobraziť zdroj- Zverejnené
- 2026-07-27 20:16:40
- Dotknuté verzie
- >=12.0.0,<15.5.21,>=16.0.0,<16.2.11
- Typ
- Webová aplikácia
- Posledná úprava
- 2026-07-29 14:38:20
- Vektor
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N