6
CVE-2026-64648
- EPSS 0.34%
- Veröffentlicht 27.07.2026 19:20:42
- Zuletzt bearbeitet 29.07.2026 14:38:20
- CVE-Watchlists
- Unerledigt
Next.js: Response Body Cache Confusion for Requests Containing Bodies
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. Confidential data in the POST's response body would then leak to unauthorized requests. Though the request itself will not be deduped. This only applies to fetch calls with a request that has a different init than the one passed to fetch. A safe request would be: fetch(new Request(init), init). An unsafe request would be: fetch(new Request(init), aDifferentInit). This issue has been fixed in versions 15.5.21 and 16.2.11.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.34% | 0.262 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
|
| security-advisories@github.com | 6 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-524 Use of Cache Containing Sensitive Information
The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.
https://github.com/vercel/next.js/releases/tag/v15.5.21
https://github.com/vercel/next.js/releases/tag/v16.2.11
https://github.com/vercel/next.js/security/advisories/GHSA-68g3-v927-f742
https://github.com/vercel/next.js/commit/062f66700b52a5d6bba2c0605d55577ab7ad262c
https://github.com/vercel/next.js/commit/73b94872bc343d09494b50394d8c08eb9fc8e56a