CVE-2025-30218: Middleware subrequest ID leakage to third parties
A vulnerability in Next.js Middleware could leak the x-middleware-subrequest-id header to third-party services during fetch requests. While exploitation is unlikely, Vercel is removing this recursion prevention logic from Middleware to achieve parity across runtimes and has already mitigated this for Vercel customers.
In the process of remediating , we looked at other possible exploits of Middleware. We independently verified this in parallel with two reports from independent researchers.CVE-2025-29927low severity vulnerability
To mitigate , Next.js validated the which persisted across multiple incoming requests:CVE-2025-29927x-middleware-subrequest-id
However, this subrequest ID is sent to all requests, even if the destination is not the same host as the Next.js application.
Initiating a fetch request to a third-party within Middleware will send the to that third party.x-middleware-subrequest-id
While the exploitation of this vulnerability is unlikely due to an attacker requiring control of the third-party, we want to be proactive. We were already planning on removing this recursion prevention logic from Middleware—it was not supported in newer updates to Middleware to support the Node.js runtime—this disclosure expedited our efforts to bring parity between runtimes.
Vercel customers are protected with mitigations already implemented within our platform environment. We still encourage teams to update to the latest Next.js patch version or their chosen backport. Other infrastructure providers which host Next.js applications are not impacted by this, as it is specific to Vercel's implementation of recursion protection.
This advisory was published in alignment with our new internal process for disclosure of vulnerabilities within OSS packages, based on . We’ve patched 15.x, and offered backports for versions 12.x through 14.x, making an exception to our newly published . our postmorten of CVE-2025-29927LTS policy
We’ve also worked proactively with new partners to Next.js for early disclosure. If you are an infrastructure provider and want to work with us, please email .partners@nextjs.org
Thank you to Jinseo Kim () and for the responsible disclosure. These researchers were awarded as part of our bug bounty program.kjsmanryotak
SummaryImpactRemediationCreditSource: original entry ↗
More from Vercel
Follow Vercel to get its new changes in your feed and email digest.
OpenAI Decisions API now available on AI Gateway
OpenAI's Decisions API is now accessible through Vercel's AI Gateway with an OpenAI-compatible endpoint, enabling decision models to answer typed questions and return probabilities, choices, and scores for routing, triage, and guardrails use cases. Support is available across the OpenAI SDK, AI SDK, HTTP API, and CLI with the latest versions.
Timestamp attributes now supported in Vercel Flags
Vercel Flags now supports timestamp attributes for entities, allowing you to create time-based targeting rules. Use this feature to run limited-time campaigns, show content between specific dates, or target users based on registration date.
Glyph Cluster now available in stealth on AI Gateway
Glyph Cluster, a reasoning model for coding and long-context analysis, is now available as a stealth model on Vercel's AI Gateway for Pro and Enterprise plan teams with purchased AI Gateway credits at no cost during the stealth period. The model supports function calling, streams responses, and can be accessed via AI SDK, OpenAI-compatible APIs, and coding agents.