Next.js: Cache confusion of response bodies for requests with bodies
Impact
A server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.
This only applies to `fetch` calls with a request that has a different init than the one passed to `fetch`.
Safe: `fetch(new Request(init), init)`
Unsafe: `fetch(new Request(init), aDifferentInit)`
Workarounds
No workaround exists besides upgrading. Applications using Pages Router are not vulnerable.
Weakness classes: CWE-524 (Use of Cache Containing Sensitive Information)
Source: GHSA-68g3-v927-f742 · GitHub Advisory Database (CC-BY-4.0) — printed from a structured Sanity dataset. ← Back to the front page