Skip to content

x-middleware-subrequest-id may be leaked to external hosts

Low
aaronbrown-vercel published GHSA-223j-4rm8-mrmf Apr 2, 2025

Package

npm next (npm)

Affected versions

12.3.5, 13.5.9, 14.2.25, 15.2.3

Patched versions

12.3.6, 13.5.10, 14.2.26, 15.2.4

Description

Summary

In the process of remediating CVE-2025-29927, we looked at other possible exploits of Middleware. We independently verified this low severity vulnerability in parallel with two reports from independent researchers.

Learn more here.

Credit

Thank you to Jinseo Kim kjsman and RyotaK (GMO Flatt Security Inc.) with takumi-san.ai for the responsible disclosure. These researchers were awarded as part of our bug bounty program.

Severity

Low

CVE ID

CVE-2025-30218

Weaknesses

No CWEs

Credits