GHSA-68g3-v927-f742
Next.js: Cache confusion of response bodies for requests with bodies
Quick fix
GHSA-68g3-v927-f742 — next: upgrade to the fixed version with the command below.
npm install next@15.5.21 Details
## Impact
A server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.
This only applies to `fetch` calls with a request that has a different init than the one passed to `fetch`. Safe: `fetch(new Request(init), init)` Unsafe: `fetch(new Request(init), aDifferentInit)`
## Workarounds
No workaround exists besides upgrading. Applications using Pages Router are not vulnerable.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/vercel/next.js/security/advisories/GHSA-68g3-v927-f742 [WEB]
- https://github.com/vercel/next.js/commit/062f66700b52a5d6bba2c0605d55577ab7ad262c [WEB]
- https://github.com/vercel/next.js/commit/73b94872bc343d09494b50394d8c08eb9fc8e56a [WEB]
- https://github.com/vercel/next.js [PACKAGE]
- https://github.com/vercel/next.js/releases/tag/v15.5.21 [WEB]
- https://github.com/vercel/next.js/releases/tag/v16.2.11 [WEB]