{"id":"CVE-2026-64648","aliases":["GHSA-68g3-v927-f742"],"title":"Next.js: Cache confusion of response bodies for requests with bodies","summary":"Next.js: Cache confusion of response bodies for requests with bodies","severity":"medium","cwe":["CWE-524"],"vendor":"next","product":"next","ecosystem":"npm","affected":["next >= 13.0.0, < 15.5.21","next >= 16.0.0, < 16.2.11"],"patched":["next 15.5.21","next 16.2.11"],"published":"2026-07-22","updated":"2026-07-22","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-68g3-v927-f742","references":[{"url":"https://github.com/vercel/next.js/security/advisories/GHSA-68g3-v927-f742"},{"url":"https://github.com/vercel/next.js/commit/062f66700b52a5d6bba2c0605d55577ab7ad262c"},{"url":"https://github.com/vercel/next.js/commit/73b94872bc343d09494b50394d8c08eb9fc8e56a"},{"url":"https://github.com/vercel/next.js/releases/tag/v15.5.21"},{"url":"https://github.com/vercel/next.js/releases/tag/v16.2.11"},{"url":"https://github.com/advisories/GHSA-68g3-v927-f742"}],"tags":["ghsa","npm"],"ingestedAt":"2026-07-23T00:08:38.922Z","epss":0.00336,"epssPercentile":0.27116,"slug":"CVE-2026-64648","body":"## Overview\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis only applies to `fetch` calls with a request that has a different init than the one passed to `fetch`.\nSafe: `fetch(new Request(init), init)`\nUnsafe: `fetch(new Request(init), aDifferentInit)`\n\n## Workarounds\n\nNo workaround exists besides upgrading. Applications using Pages Router are not vulnerable.\n\n## Affected packages\n\n- `next >= 13.0.0, < 15.5.21`\n- `next >= 16.0.0, < 16.2.11`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `next 15.5.21`\n- `next 16.2.11`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}