Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-9629 | Next.js may leak x-middleware-subrequest-id to external hosts |
Github GHSA |
GHSA-223j-4rm8-mrmf | Next.js may leak x-middleware-subrequest-id to external hosts |
Wed, 10 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:vercel:next.js:12.3.5:*:*:*:*:node.js:*:* cpe:2.3:a:vercel:next.js:13.5.9:*:*:*:*:node.js:*:* cpe:2.3:a:vercel:next.js:14.2.25:*:*:*:*:node.js:*:* cpe:2.3:a:vercel:next.js:15.2.3:*:*:*:*:node.js:*:* |
|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 04 Apr 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Thu, 03 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Apr 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Next.js is a React framework for building full-stack web applications. To mitigate CVE-2025-29927, Next.js validated the x-middleware-subrequest-id which persisted across multiple incoming requests. However, this subrequest ID is sent to all requests, even if the destination is not the same host as the Next.js application. Initiating a fetch request to a third-party within Middleware will send the x-middleware-subrequest-id to that third party. This vulnerability is fixed in 12.3.6, 13.5.10, 14.2.26, and 15.2.4. | |
| Title | Next.js may leak x-middleware-subrequest-id to external hosts | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-10-13T15:37:02.310Z
Reserved: 2025-03-18T18:15:13.850Z
Link: CVE-2025-30218
Updated: 2025-04-03T13:44:06.596Z
Status : Analyzed
Published: 2025-04-02T22:15:19.940
Modified: 2025-09-10T15:14:08.560
Link: CVE-2025-30218
OpenCVE Enrichment
Updated: 2025-07-12T15:26:05Z
EUVD
Github GHSA