Insertion of Sensitive Information Into Sent Data in Next.js - CVE-2026-64643
Published: July 22, 2026
Next.js
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose internal Server Function endpoints.
The vulnerability exists due to insertion of sensitive information into sent data in publicly served client artifacts when exposing Server Action references. A remote attacker can access client artifacts containing action references to disclose internal Server Function endpoints.
This affects applications using App Router with Server Actions or use cache, and the disclosure is typically a recon or enumeration primitive.