Server-side Fetch Vulnerability in Next.js Framework by Vercel
CVE-2026-64647

6.3MEDIUM

Key Information:

Vendor

Vercel

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-64647?

Next.js, a popular React framework, has a vulnerability that allows a server-side fetch with varying request bodies to return cached responses from different requests to the same URL. This issue specifically targets request bodies with content types other than UTF-8, potentially leading to unauthorized access to sensitive data in POST responses. The vulnerability affects versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, but has been addressed in newer releases (15.5.21 and 16.2.11).

Affected Version(s)

next.js >= 13.0.0, < 15.5.21 < 13.0.0, 15.5.21

next.js >= 16.0.0, < 16.2.11 < 16.0.0, 16.2.11

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.