CVE-2025-57822: Vercel Next.js
High severity, CVSS 8.2. EPSS: 2.5% chance of exploitation in the next 30 days.
Next.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next() was used without explicitly passing the request object, it could lead to SSRF in self-hosted applications that incorrectly forwarded user-supplied headers. This vulnerability has been fixed in Next.js versions 14.2.32 and 15.4.7. All users implementing custom middleware logic in self-hosted environments are strongly encouraged to upgrade and verify correct usage of the next() function.
Affected products
- Vercel Next.js: before 14.2.32 (fixed in 14.2.32); from 15.0.0, before 15.4.7 (fixed in 15.4.7)
Published 2025-08-29. Last modified 2026-06-17.