Skip to content
VulniPulse
Advisory severityMedium5.3Red Hat Linux

Medium [CVE-2026-64643] Information disclosure via Server Action ID exposure

This medium-severity Red Hat Linux advisory covers CVE-2026-64643 affecting Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-64643 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxRed Hat Enterprise Linux
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, Next.js applications using App Router, Server Actions (use server) or use cache endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually used.

Server Action IDs can be disclosed to unauthenticated users via publicly served client artifacts (for example, static chunks containing action references). By itself, this disclosure is typically a recon/enumeration primitive; however, it can increase risk when combined with other weaknesses.

This issue has been fixed in versions 15.5.21 and 16.2.11. A flaw was found in Next.js.

This bypasses authentication on pages where these endpoints are used, leading to information disclosure. This Moderate information disclosure vulnerability in Next.js applications allows unauthenticated users to obtain Server Action IDs from publicly served client artifacts.

While primarily a reconnaissance primitive, this exposure could increase overall risk when chained with other weaknesses. Red Hat products and services that incorporate Next.js, such as Red Hat AMQ, Red Hat Enterprise Linux AI, and cloud.redhat.com offerings, are affected.

Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-201.

Affected versions
  • 12.0.0
  • 15.5.20
  • 16.0.0
  • 16.2.10

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Fixed versions
  • 15.5.21
  • 16.2.11

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Mitigation

Upgrade to a fixed release: 15.5.21, 16.2.11. That is the remediation for this advisory.

The vendor advisory may list additional interim mitigations or workarounds not captured here — review it before change work.

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.