CVE-2026-64648
MEDIUMNext.js: Response Body Cache Confusion for Requests Containing Bodies
Title source: cnaDescription
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. Confidential data in the POST's response body would then leak to unauthorized requests. Though the request itself will not be deduped. This only applies to fetch calls with a request that has a different init than the one passed to fetch. A safe request would be: fetch(new Request(init), init). An unsafe request would be: fetch(new Request(init), aDifferentInit). This issue has been fixed in versions 15.5.21 and 16.2.11.
References (5)
Core 5
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/vercel/next.js/security/advisories/GHSA-68g3-v927-f742
X_Refsource_Misc x_refsource_misc
https://github.com/vercel/next.js/commit/062f66700b52a5d6bba2c0605d55577ab7ad262c
X_Refsource_Misc x_refsource_misc
https://github.com/vercel/next.js/commit/73b94872bc343d09494b50394d8c08eb9fc8e56a
X_Refsource_Misc x_refsource_misc
https://github.com/vercel/next.js/releases/tag/v15.5.21
X_Refsource_Misc x_refsource_misc
https://github.com/vercel/next.js/releases/tag/v16.2.11
Scores
CVSS v4
6.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Details
CWE
CWE-524
Status
published
Products (2)
vercel/next.js
>= 13.0.0, < 15.5.21
vercel/next.js
>= 16.0.0, < 16.2.11
Published
Jul 27, 2026
Tracked Since
Jul 28, 2026