Junglewise Threat Intelligence

CVE-2025-30218: Vercel Next.js information exposure in Middleware subrequest ID

CVE-2025-30218 · Severity: medium · CVSS 4 · Published 2025-04-02

Technologies: Vercel Next.js. Vendors: Vercel.

Executive brief

Next.js is a popular framework used for building web applications. A security issue was identified where internal tracking IDs used for managing requests could be accidentally sent to external third-party websites. While the risk is low, an attacker who controls a third-party service called by the application could potentially see these internal identifiers, which might be used to facilitate more complex attacks.

Technical details

A sensitive information exposure vulnerability (CWE-200) exists in Next.js Middleware. To prevent request recursion, Next.js uses an 'x-middleware-subrequest-id' header; however, versions prior to the fix automatically attached this header to all outgoing fetch requests initiated within Middleware, including those directed at external third-party domains. An attacker controlling an external endpoint could capture this ID. The vulnerability is specific to Vercel's implementation of recursion protection. Patches have been released in versions 12.3.6, 13.5.10, 14.2.26, and 15.2.4.

Affected products

  • Vercel next.js 12.3.5, 13.5.9, 14.2.25, 15.2.3

Timeline

  • 2025-04-02: disclosed
  • 2025-04-02: patched
  • 2025-04-02: advisory

References

Related threats