Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.5 npm

Next.js Improper Middleware Redirect Handling Leads to SSRF

GHSA-4342-x723-ch2f · CVE-2025-57822

Published · Modified

Description

A vulnerability in Next.js Middleware has been fixed in v14.2.32 and v15.4.7. The issue occurred when request headers were directly passed into NextResponse.next(). In self-hosted applications, this could allow Server-Side Request Forgery (SSRF) if certain sensitive headers from the incoming request were reflected back into the response.

All users implementing custom middleware logic in self-hosted environments are strongly encouraged to upgrade and verify correct usage of the next() function.

More details at Vercel Changelog

Ready to move

Start Securing

Free, no credit card | First findings in minutes