Next.js may leak x-middleware-subrequest-id to external hosts
Package
Affected versions
= 12.3.5
= 13.5.9
= 14.2.25
= 15.2.3
Patched versions
12.3.6
13.5.10
14.2.26
15.2.4
Description
Published by the National Vulnerability Database
Apr 2, 2025
Published to the GitHub Advisory Database
Apr 2, 2025
Reviewed
Apr 2, 2025
Last updated
Apr 3, 2025
Summary
In the process of remediating CVE-2025-29927, we looked at other possible exploits of Middleware. We independently verified this low severity vulnerability in parallel with two reports from independent researchers.
Learn more here.
Credit
Thank you to Jinseo Kim kjsman and RyotaK (GMO Flatt Security Inc.) with takumi-san.ai for the responsible disclosure. These researchers were awarded as part of our bug bounty program.
References