{"id":"CVE-2025-30218","aliases":["GHSA-223j-4rm8-mrmf"],"url":"https://o3.security/vulnerability/CVE-2025-30218","summary":"Next.js may leak x-middleware-subrequest-id to external hosts","details":"Next.js is a React framework for building full-stack web applications. To mitigate CVE-2025-29927, Next.js validated the x-middleware-subrequest-id which persisted across multiple incoming requests. However, this subrequest ID is sent to all requests, even if the destination is not the same host as the Next.js application. Initiating a fetch request to a third-party within Middleware will send the x-middleware-subrequest-id to that third party. This vulnerability is fixed in 12.3.6, 13.5.10, 14.2.26, and 15.2.4.","published":"2025-04-02T21:23:14.660Z","modified":"2026-08-12T03:51:12.278754514Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"next","fixedVersion":"12.3.6"},{"ecosystem":"npm","name":"next","fixedVersion":"13.5.10"},{"ecosystem":"npm","name":"next","fixedVersion":"14.2.26"},{"ecosystem":"npm","name":"next","fixedVersion":"15.2.4"}],"fix":null,"references":[{"type":"WEB","url":"https://vercel.com/changelog/cve-2025-30218-5DREmEH765PoeAsrNNQj3O"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30218.json"},{"type":"ADVISORY","url":"https://github.com/vercel/next.js/security/advisories/GHSA-223j-4rm8-mrmf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30218"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:12.278754514Z"}}