CVE Explorer
CVE-2026-64647
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. Confidential data in the POST's response body would then leak to unauthorized requests. Though the request itself will not be deduped. This is only an issue when receiving request bodies with a content type charset other than UTF-8
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"next.js","vendor":"vercel","versions":[{"status":"affected","version":">= 13.0.0, < 15.5.21"},{"status":"affected","version":">= 16.0.0, < 16.2.11"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:476c727ddf48d822edf48c161650a8e72fd3b6330f5f07b282e7f77afd4b3405 · sha256:b566d5e1748bd7b9… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":6.3,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:476c727ddf48d822edf48c161650a8e72fd3b6330f5f07b282e7f77afd4b3405 · sha256:b566d5e1748bd7b9… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-116","description":"CWE-116: Improper Encoding or Escaping of Output","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:476c727ddf48d822edf48c161650a8e72fd3b6330f5f07b282e7f77afd4b3405 · sha256:b566d5e1748bd7b9… · /containers/cna/problemTypes/0/descriptions/0
Source references
5 source assertions{"name":"https://github.com/vercel/next.js/commit/025bf4a5f7b47fb7758c4ebf1c931a61c451c082","tags":["x_refsource_MISC"],"url":"https://github.com/vercel/next.js/commit/025bf4a5f7b47fb7758c4ebf1c931a61c451c082"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:476c727ddf48d822edf48c161650a8e72fd3b6330f5f07b282e7f77afd4b3405 · sha256:b566d5e1748bd7b9… · /containers/cna/references/2
{"name":"https://github.com/vercel/next.js/pull/96008","tags":["x_refsource_MISC"],"url":"https://github.com/vercel/next.js/pull/96008"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:476c727ddf48d822edf48c161650a8e72fd3b6330f5f07b282e7f77afd4b3405 · sha256:b566d5e1748bd7b9… · /containers/cna/references/1
{"name":"https://github.com/vercel/next.js/releases/tag/v15.5.21","tags":["x_refsource_MISC"],"url":"https://github.com/vercel/next.js/releases/tag/v15.5.21"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:476c727ddf48d822edf48c161650a8e72fd3b6330f5f07b282e7f77afd4b3405 · sha256:b566d5e1748bd7b9… · /containers/cna/references/3
{"name":"https://github.com/vercel/next.js/releases/tag/v16.2.11","tags":["x_refsource_MISC"],"url":"https://github.com/vercel/next.js/releases/tag/v16.2.11"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:476c727ddf48d822edf48c161650a8e72fd3b6330f5f07b282e7f77afd4b3405 · sha256:b566d5e1748bd7b9… · /containers/cna/references/4
{"name":"https://github.com/vercel/next.js/security/advisories/GHSA-4633-3j49-mh5q","tags":["x_refsource_CONFIRM"],"url":"https://github.com/vercel/next.js/security/advisories/GHSA-4633-3j49-mh5q"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:476c727ddf48d822edf48c161650a8e72fd3b6330f5f07b282e7f77afd4b3405 · sha256:b566d5e1748bd7b9… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.