CVE-2026-64648

Red Hat Security Advisory: Streams for Apache Kafka 3.2.1 release and security update

Beschreibung

Next.js ist ein React-Framework zum Erstellen von Full-Stack-Webanwendungen. In den Versionen 12.0.0 bis 15.5.20 und 16.0.0 bis 16.2.10 kann eine serverseitige Abfrage mit einem Anfragetext einen zwischengespeicherten Antworttext von einer anderen Anfrage zur gleichen URL, aber mit unterschiedlichem Text zurückgeben. Vertrauliche Daten im Antworttext des POST würden dann an nicht autorisierte Anfragen durchsickern. Obwohl die Anfrage selbst nicht dedupliziert wird. Dies gilt nur für Fetch-Aufrufe mit einer Anfrage, die einen anderen init als den hat, der an fetch übergeben wurde. Eine sichere Anfrage wäre: `fetch(new Request(init), init)`. Eine unsichere Anfrage wäre: `fetch(new Request(init), aDifferentInit)`. Dieses Problem wurde in den Versionen 15.5.21 und 16.2.11 behoben.

Metriken

Severity
medium
kein öffentlicher PoC bekannt
6.0
Quelle: nvd-v4
30.5 %
Erhöht — CVE ist relevanter als mindestens 10 % der heute bewerteten CVEs.
0.4 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-12 19:35 UTC
CWE-524

Weakness-Klassen (CWE)

  • CWE-524Base

    Use of Cache Containing Sensitive Information

    The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. Initial Analysis2026-07-29 14:38 UTC· nvd@nist.gov
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
    • CPE Configuration: OR *cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:* versions from (including) 16.0.0 up to (excluding) 16.2.11 *cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:* versions from (including) 12.0.0 up to (excluding) 15.5.21
    • Reference Type: GitHub, Inc.: https://github.com/vercel/next.js/commit/062f66700b52a5d6bba2c0605d55577ab7ad262c Types: Patch
    • Reference Type: GitHub, Inc.: https://github.com/vercel/next.js/commit/73b94872bc343d09494b50394d8c08eb9fc8e56a Types: Patch
  2. CVE Modified2026-07-28 15:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-64648","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  3. New CVE Received2026-07-27 20:16 UTC· security-advisories@github.com
    • Affected: next.js
    • Description: Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. Confidential data in the POST's response body would then leak to unauthorized requests. Though the request itself will not be deduped. This only applies to fetch calls with a request that has a different init than the one passed to fetch. A safe request would be: fetch(new Request(init), init). An unsafe request would be: fetch(new Request(init), aDifferentInit). This issue has been fixed in versions 15.5.21 and 16.2.11.
    • CVSS V4.0: AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    • CWE: CWE-524

Betroffene Betriebssysteme

  • linux

    ubuntu / nettynoble

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • apache

    kafka2.8.0 – 3.9.2

  • apache

    kafka4.0.0 – 4.0.2

  • apache

    kafka4.1.0 – 4.1.2

  • Atlassian

    BambooData Center LTS 10.2.22

  • Atlassian

    BambooData Center LTS 12.1.10

  • Atlassian

    BitbucketData Center 10.4.2

  • Atlassian

    BitbucketData Center LTS 10.2.6

  • Atlassian

    BitbucketData Center LTS 9.4.23

  • Atlassian

    ConfluenceData Center LTS 10.2.15

  • Atlassian

    ConfluenceData Center LTS 9.2.23

  • Atlassian

    Crucible4.9.13

  • Atlassian

    Fisheye4.9.13

  • Atlassian

    JiraData Center LTS 10.3.24

  • Atlassian

    JiraData Center LTS 11.3.10

  • bitnami

    golang1.26.0-0

  • eclipse

    vert.x4.0.0 – 4.5.29

  • eclipse

    vert.x5.0.0 – 5.1.4

  • go

    stdlib1.26.0-0

  • golang

    go1.26.0 – 1.26.2

  • golang

    go1.26.0 – 1.26.3

  • golang

    go1.25.10

  • golang

    go1.25.9

  • golang

    net0.55.0

  • IBM

    QRadar SIEM<7.5.0 UP15 IF06

Quellen & Referenzen

Verknüpfte CVEs

33 weitere CVEs anzeigen
IDCVE-2026-64648