mediumVulnerability

CVE-2026-64643

## Impact In Next.js applications using App Router, Server Actions (`use server`) or `use cache` endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually used. Server Action IDs can be disclosed to unauthenticated users via publicly served client artifacts (for example, static chunks containing action references). Affected users are applications using App Router + Server Actions. By itself, this disclosure is typically a recon/enumeration primitive; however, it can increase risk when combined with other weaknesses. ## Workarounds Never assume any authentication claims at the `use cache` or `use server` boundary. Always authenticate within the boundary.

Properties

ghsa_id
GHSA-955p-x3mx-jcvp
severity
medium
summary
Next.js: Unauthenticated disclosure of internal Server Function endpoints
epss_score
0.00516
cve_id
CVE-2026-64643
is_ghsa_only
false
ghsa_published
2026-07-22T23:00:34Z
source_url
https://github.com/advisories/GHSA-955p-x3mx-jcvp
epss_percentile
0.41961
ghsa_updated
2026-07-22T23:00:35Z

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/next

AFFECTS (1)

[Software]npm/next

HAS_WEAKNESS (1)

[Weakness]Insertion of Sensitive Information Into Sent Data

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-64643 — Ninja Signal Threat Intelligence | Ninja Signal