Server-side Fetch Vulnerability in Next.js Framework by Vercel
CVE-2026-64647
6.3MEDIUM
What is CVE-2026-64647?
Next.js, a popular React framework, has a vulnerability that allows a server-side fetch with varying request bodies to return cached responses from different requests to the same URL. This issue specifically targets request bodies with content types other than UTF-8, potentially leading to unauthorized access to sensitive data in POST responses. The vulnerability affects versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, but has been addressed in newer releases (15.5.21 and 16.2.11).
Affected Version(s)
next.js >= 13.0.0, < 15.5.21 < 13.0.0, 15.5.21
next.js >= 16.0.0, < 16.2.11 < 16.0.0, 16.2.11