Junglewise Threat Intelligence

CVE-2025-57822: Vercel Next.js server-side request forgery in middleware

CVE-2025-57822 · Severity: low · CVSS 3.1 · Published 2025-08-29

Technologies: Vercel Next.js. Vendors: Vercel.

Executive brief

Next.js is a popular React framework used by developers to build web applications. When using custom middleware logic in self-hosted deployments, a flaw in how request headers are handled can allow attackers to trigger requests to arbitrary internal systems (server-side request forgery). This could expose sensitive internal services or lead to unauthorized data access, though Vercel's managed platform is not affected.

Technical details

The vulnerability exists in Next.js middleware when developers pass request headers directly into NextResponse.next() without properly using the request object parameter. Specifically, if middleware reflects user-controlled headers (such as the Location header) back into the response without validation, an attacker can manipulate these headers to cause the middleware to route requests to attacker-controlled destinations. This is a Server-Side Request Forgery (CWE-918) vulnerability. The issue affects versions before 14.2.32 and 15.4.7 and requires self-hosted deployments where developers use custom middleware and do not follow documented best practices. The fix prevents unsafe fallback behavior by requiring explicit passing of the request object and validates that user-supplied headers do not alter internal routing logic. Patches are available in Next.js v14.2.32 and v15.4.7.

Affected products

  • Vercel Next.js <14.2.32, 15.0.0-canary.0 to <15.4.7

Timeline

  • 2025-08-29: disclosed: Vulnerability disclosed in GHSA-4342-x723-ch2f
  • 2025-08-25: patched: Patch applied on August 25th, 2025 for Vercel customers
  • 2025-08-29: other: CVE-2025-57822 assigned

References

Related threats