---
id: CVE-2026-64647
aliases:
  - GHSA-4633-3j49-mh5q
title: >-
  Next.js: Cache confusion of response bodies for requests with bodies
  containing invalid UTF-8 byte sequences
summary: >-
  Next.js: Cache confusion of response bodies for requests with bodies
  containing invalid UTF-8 byte sequences
severity: medium
cwe:
  - CWE-116
vendor: next
product: next
ecosystem: npm
affected:
  - 'next >= 13.0.0, < 15.5.21'
  - 'next >= 16.0.0, < 16.2.11'
patched:
  - next 15.5.21
  - next 16.2.11
published: '2026-07-22'
updated: '2026-07-22'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-4633-3j49-mh5q'
references:
  - url: 'https://github.com/vercel/next.js/security/advisories/GHSA-4633-3j49-mh5q'
  - url: 'https://github.com/vercel/next.js/pull/96008'
  - url: >-
      https://github.com/vercel/next.js/commit/025bf4a5f7b47fb7758c4ebf1c931a61c451c082
  - url: 'https://github.com/vercel/next.js/releases/tag/v15.5.21'
  - url: 'https://github.com/vercel/next.js/releases/tag/v16.2.11'
  - url: 'https://github.com/advisories/GHSA-4633-3j49-mh5q'
tags:
  - ghsa
  - npm
ingestedAt: '2026-07-22T23:07:32.131Z'
epss: 0.00317
epssPercentile: 0.21951
---

## Overview

## Impact

A server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.

This is only an issue when receiving request bodies with a content type charset other than UTF-8. For example, the UTF-16 byte sequences for `삃삃` and `섄섄` in the request body would share the same cache.

## Workarounds

If you cannot upgrade, consider only making fetch requests with UTF-8 bodies (default in Next.js). Applications using Pages Router are not vulnerable.

## Affected packages

- `next >= 13.0.0, < 15.5.21`
- `next >= 16.0.0, < 16.2.11`

## Remediation

Upgrade to a patched release:

- `next 15.5.21`
- `next 16.2.11`
