---
id: CVE-2026-64648
aliases:
  - GHSA-68g3-v927-f742
title: 'Next.js: Cache confusion of response bodies for requests with bodies'
summary: 'Next.js: Cache confusion of response bodies for requests with bodies'
severity: medium
cwe:
  - CWE-524
vendor: next
product: next
ecosystem: npm
affected:
  - 'next >= 13.0.0, < 15.5.21'
  - 'next >= 16.0.0, < 16.2.11'
patched:
  - next 15.5.21
  - next 16.2.11
published: '2026-07-22'
updated: '2026-07-22'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-68g3-v927-f742'
references:
  - url: 'https://github.com/vercel/next.js/security/advisories/GHSA-68g3-v927-f742'
  - url: >-
      https://github.com/vercel/next.js/commit/062f66700b52a5d6bba2c0605d55577ab7ad262c
  - url: >-
      https://github.com/vercel/next.js/commit/73b94872bc343d09494b50394d8c08eb9fc8e56a
  - url: 'https://github.com/vercel/next.js/releases/tag/v15.5.21'
  - url: 'https://github.com/vercel/next.js/releases/tag/v16.2.11'
  - url: 'https://github.com/advisories/GHSA-68g3-v927-f742'
tags:
  - ghsa
  - npm
ingestedAt: '2026-07-23T00:08:38.922Z'
epss: 0.00336
epssPercentile: 0.27117
---

## Overview

## Impact

A server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.

This only applies to `fetch` calls with a request that has a different init than the one passed to `fetch`.
Safe: `fetch(new Request(init), init)`
Unsafe: `fetch(new Request(init), aDifferentInit)`

## Workarounds

No workaround exists besides upgrading. Applications using Pages Router are not vulnerable.

## Affected packages

- `next >= 13.0.0, < 15.5.21`
- `next >= 16.0.0, < 16.2.11`

## Remediation

Upgrade to a patched release:

- `next 15.5.21`
- `next 16.2.11`
