CVE-2025-30218 – next
Package
Manager: npm
Name: next
Vulnerable Version: =12.3.5 || >=12.3.5 <12.3.6 || =13.5.9 || >=13.5.9 <13.5.10 || =14.2.25 || >=14.2.25 <14.2.26 || =15.2.3 || >=15.2.3 <15.2.4
Severity
Level: Low
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U
EPSS: 0.00053 pctl0.16272
Details
Next.js may leak x-middleware-subrequest-id to external hosts ## Summary In the process of remediating [CVE-2025-29927](https://github.com/advisories/GHSA-f82v-jwr5-mffw), we looked at other possible exploits of Middleware. We independently verified this low severity vulnerability in parallel with two reports from independent researchers. Learn more [here](https://vercel.com/changelog/cve-2025-30218-5DREmEH765PoeAsrNNQj3O). ## Credit Thank you to Jinseo Kim [kjsman](https://hackerone.com/kjsman?type=user) and [RyotaK](https://hackerone.com/ryotak?type=user) (GMO Flatt Security Inc.) with [takumi-san.ai](https://takumi-san.ai) for the responsible disclosure. These researchers were awarded as part of our bug bounty program.
Metadata
Created: 2025-04-02T22:35:37Z
Modified: 2025-04-03T13:24:25Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-223j-4rm8-mrmf/GHSA-223j-4rm8-mrmf.json
CWE IDs: ["CWE-200"]
Alternative ID: GHSA-223j-4rm8-mrmf
Finding: F017
Auto approve: 1