CVE-2026-64648 | Vercel Next.js up to 15.5.20/16.2.10 Server-side Fetch Cache fetch init information disclosure

SecurityVulns

A vulnerability labeled as problematic has been found in Vercel Next.js up to 15.5.20/16.2.10. The affected element is the function fetch of the component Server-side Fetch Cache. Executing a manipulation of the argument init can lead to information disclosure.

The identification of this vulnerability is CVE-2026-64648. The attack may be launched remotely. There is no exploit available.

The affected component should be upgraded.VulDB Recent EntriesRead More