VDB
Sign up
MEDIUM6.5

GHSA-4342-x723-ch2f

Next.js Improper Middleware Redirect Handling Leads to SSRF

Quick fix

GHSA-4342-x723-ch2f — next: upgrade to the fixed version with the command below.

npm install next@14.2.32

Details

A vulnerability in **Next.js Middleware** has been fixed in **v14.2.32** and **v15.4.7**. The issue occurred when request headers were directly passed into `NextResponse.next()`. In self-hosted applications, this could allow Server-Side Request Forgery (SSRF) if certain sensitive headers from the incoming request were reflected back into the response.

All users implementing custom middleware logic in self-hosted environments are strongly encouraged to upgrade and verify correct usage of the `next()` function.

More details at [Vercel Changelog](https://vercel.com/changelog/cve-2025-57822)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/next
Introduced in: 0.9.9Fixed in: 14.2.32
Fixnpm install next@14.2.32
npm/next
Introduced in: 15.0.0-canary.0Fixed in: 15.4.7
Fixnpm install next@15.4.7

References