Launch Week Day 1: Announcing Security Design Review
UNKNOWN npm

Next.js may leak x-middleware-subrequest-id to external hosts

GHSA-223j-4rm8-mrmf · CVE-2025-30218

Published · Modified

Description

Summary

In the process of remediating CVE-2025-29927, we looked at other possible exploits of Middleware. We independently verified this low severity vulnerability in parallel with two reports from independent researchers.

Learn more here.

Credit

Thank you to Jinseo Kim kjsman and RyotaK (GMO Flatt Security Inc.) with takumi-san.ai for the responsible disclosure. These researchers were awarded as part of our bug bounty program.

Ready to move

Start Securing

Free, no credit card | First findings in minutes