{"id":"CVE-2026-64647","aliases":["GHSA-4633-3j49-mh5q"],"title":"Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences","summary":"Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences","severity":"medium","cwe":["CWE-116"],"vendor":"next","product":"next","ecosystem":"npm","affected":["next >= 13.0.0, < 15.5.21","next >= 16.0.0, < 16.2.11"],"patched":["next 15.5.21","next 16.2.11"],"published":"2026-07-22","updated":"2026-07-22","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-4633-3j49-mh5q","references":[{"url":"https://github.com/vercel/next.js/security/advisories/GHSA-4633-3j49-mh5q"},{"url":"https://github.com/vercel/next.js/pull/96008"},{"url":"https://github.com/vercel/next.js/commit/025bf4a5f7b47fb7758c4ebf1c931a61c451c082"},{"url":"https://github.com/vercel/next.js/releases/tag/v15.5.21"},{"url":"https://github.com/vercel/next.js/releases/tag/v16.2.11"},{"url":"https://github.com/advisories/GHSA-4633-3j49-mh5q"}],"tags":["ghsa","npm"],"ingestedAt":"2026-07-22T23:07:32.131Z","epss":0.00351,"epssPercentile":0.28844,"slug":"CVE-2026-64647","body":"## Overview\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis is only an issue when receiving request bodies with a content type charset other than UTF-8. For example, the UTF-16 byte sequences for `삃삃` and `섄섄` in the request body would share the same cache.\n\n## Workarounds\n\nIf you cannot upgrade, consider only making fetch requests with UTF-8 bodies (default in Next.js). Applications using Pages Router are not vulnerable.\n\n## Affected packages\n\n- `next >= 13.0.0, < 15.5.21`\n- `next >= 16.0.0, < 16.2.11`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `next 15.5.21`\n- `next 16.2.11`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}