CVE-2025-57822

Next.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next() was used without explicitly passing the request object, it could lead to SSRF in self-hosted applications that incorrectly forwarded user-supplied headers. This vulnerability has been fixed in Next.js versions 14.2.32 and 15.4.7. All users implementing custom middleware logic in self-hosted environments are strongly encouraged to upgrade and verify correct usage of the next() function.

GitHub Logohttps://github.com/l3montree-dev/devguard/issues/1091
Open
LOW (3.8)

Add a comment

Mark as False Positive
Comment will be synced with https://github.com/l3montree-dev/devguard/issues/1091
Last calculated at:

Affected component

next

Installed version:
15.3.5
Fixed in:
15.4.7

Quick Fix

Update all Dependencies
Update only next

Management decisions across the organization

Copyright © 2025 L3montree GmbH and the DevGuard Contributors. All rights reserved. Version 2ab7b793efd72421aea8c3a994ac60202bf1b3a5