VDB
KO
HIGH

GHSA-p9j2-gv94-2wf4

Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname

Quick fix

GHSA-p9j2-gv94-2wf4 — next: upgrade to the fixed version with the command below.

npm install next@15.5.21

Details

## Impact

A `rewrites()` or `redirects()` rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A `redirects()` rule configured this way is vulnerable to an Open Redirect.

This affects any destination that puts a dynamic segment in the hostname, whether from the path:

```javascript // next.config.js module.exports = { async rewrites() { return [ { source: '/:tenant', destination: 'https://:tenant.api.example.com', }, ] }, } ```

or from a `has` capture:

```javascript // next.config.js module.exports = { async rewrites() { return [ { source: '/', has: [{ type: 'query', key: 'region', value: '(?<region>.+)' }], destination: 'https://:region.api.example.com', }, ] }, } ```

## Workarounds

If you cannot upgrade immediately, do not build the hostname of an external `rewrites()` or `redirects()` destination from user-controlled input. If a dynamic subdomain is required, constrain the value to hostname-safe characters: `value: '(?<region>[a-z0-9-]+)'`.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / next
Introduced in: 12.0.0 Fixed in: 15.5.21
Fix npm install next@15.5.21
npm / next
Introduced in: 16.0.0 Fixed in: 16.2.11
Fix npm install next@16.2.11

References