megachangelog
Security14.2.32, 15.4.7

CVE-2025-57822: SSRF vulnerability in Next.js middleware patched

A Server-Side Request Forgery vulnerability in Next.js middleware (versions before v14.2.32 and v15.4.7) has been patched. The issue allowed misconfigured middleware that reflected user request headers to unintentionally route requests to attacker-controlled destinations, exploitable in self-hosted deployments.

Summary

Impact

Resolution

Workarounds

Credit

References

A vulnerability affecting has been addressed. It impacted versions prior to and , and involved a risk introduced by misconfigured usage of the function within middleware. Applications that reflected a user's request headers in this function, rather than passing them through the object, could unintentionally allow the server to issue requests to attacker-controlled destinations. Next.js Middlewarev14.2.32v15.4.7Server-Side Request Forgery (SSRF)NextResponse.next()request

A patch applied on August 25th, 2025 eliminated exposure for Vercel customers running the affected versions.

In affected configurations, an attacker could:

This issue is exploitable in self-hosted deployments where developers use custom middleware logic and do not adhere to documented usage of . It is on Vercel infrastructure, which isolates and protects internal request behavior.NextResponse.next({ request })not exploitable

The issue was resolved by updating the internal middleware logic to prevent unsafe fallback behavior when is omitted from the call. This ensures the origin server behavior cannot be unintentionally altered by user-supplied headers or misrouted requests.requestnext()

Fix available in:

For users who cannot upgrade immediately:

Thanks to at RootSys, and and the for their responsible disclosure.Dominik ProdingerNicolas Lamoureux Latacora team

Read more

  • Influence the destination of internal requests triggered by middleware routing logic

  • Perform SSRF against internal infrastructure if user-controlled headers (e.g.,

    ) were forwarded or interpreted without validationLocation

  • Potentially access sensitive internal resources or services unintentionally exposed via internal redirect behavior

  • Next.js v14.2.32

  • Next.js v15.4.7

  • Ensure middleware follows official guidance: Use to explicitly pass the request objectNextResponse.next({ request })

  • Avoid forwarding user-controlled headers to downstream systems without validation

  • Ensure headers that should never be sent from client to server are not reflected back to the client via , such as .NextResponse.nextLocation

securityssrfmiddlewarenext.jscve

Source: original entry ↗

More from Vercel

Follow Vercel to get its new changes in your feed and email digest.

Feature

OpenAI Decisions API now available on AI Gateway

OpenAI's Decisions API is now accessible through Vercel's AI Gateway with an OpenAI-compatible endpoint, enabling decision models to answer typed questions and return probabilities, choices, and scores for routing, triage, and guardrails use cases. Support is available across the OpenAI SDK, AI SDK, HTTP API, and CLI with the latest versions.

ai-gatewayopenaiapidecisionssdks
Feature

Timestamp attributes now supported in Vercel Flags

Vercel Flags now supports timestamp attributes for entities, allowing you to create time-based targeting rules. Use this feature to run limited-time campaigns, show content between specific dates, or target users based on registration date.

flagstargetingfeaturetimestampscampaigns
Feature

Glyph Cluster now available in stealth on AI Gateway

Glyph Cluster, a reasoning model for coding and long-context analysis, is now available as a stealth model on Vercel's AI Gateway for Pro and Enterprise plan teams with purchased AI Gateway credits at no cost during the stealth period. The model supports function calling, streams responses, and can be accessed via AI SDK, OpenAI-compatible APIs, and coding agents.

ai-gatewaymodelscodingstealth
See all Vercel changes →