What is CVE-2026-64647?
This vulnerability involves a caching issue with server-side fetch in Next.js. Requests to the same URL with different POST bodies may return cached responses from other requests, potentially leaking confidential data. Users of versions 12.0.0–15.5.20 and 16.0.0–16.2.10 should apply the relevant security patches immediately.
Azərbaycanca: Bu boşluq Next.js framework-də server-side fetch əməliyyatlarında cache-lə bağlıdır. Eyni URL-ə fərqli POST body-ləri ilə edilən sorğular zamanı cache-dən səhv cavab qayıda bilər, bu isə məxfi məlumatların sızmasına səbəb ola bilər. 12.0.0–15.5.20 və 16.0.0–16.2.10 versiyaları istifadəçiləri dərhal müvafiq təhlükəsizlik yeniləmələrini tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
During which operation can the CVE-2026-64647 vulnerability in Next.js lead to confidential data leakage?
This vulnerability involves a caching issue with server-side fetch in Next.js. Requests to the same URL with different POST bodies may return cached responses from other requests.
Which versions of Next.js are affected by the CVE-2026-64647 vulnerability?
Versions 12.0.0–15.5.20 and 16.0.0–16.2.10 are affected. Users of these versions should apply the relevant security patches immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.