Description
Next.js is a React framework for building full-stack web applications. To mitigate CVE-2025-29927, Next.js validated the x-middleware-subrequest-id which persisted across multiple incoming requests. However, this subrequest ID is sent to all requests, even if the destination is not the same host as the Next.js application. Initiating a fetch request to a third-party within Middleware will send the x-middleware-subrequest-id to that third party. This vulnerability is fixed in 12.3.6, 13.5.10, 14.2.26, and 15.2.4.
Remediation
References
Related Vulnerabilities
WordPress Plugin WordPress Books Gallery Security Bypass (3.5)
WordPress Plugin WP Js External Link Info Cross-Site Scripting (1.21)
Oracle HTTP Server Other Vulnerability (CVE-2020-29506)
PHP Numeric Errors Vulnerability (CVE-2011-0755)
WordPress Plugin Secure Copy Content Protection and Content Locking SQL Injection (2.6.6)