CVE-2025-57822 is a Server-Side Request Forgery (SSRF) vulnerability affecting self-hosted Next.js applications prior to versions 14.2.32 and 15.4.7. It arises when the next() function is used without explicitly passing the request object, allowing attackers to manipulate user-supplied headers. With a CVSS score of 8.2 (HIGH), this vulnerability is easily exploitable over the network with low attack complexity, potentially leading to high confidentiality impact. While not currently on the KEV catalog or actively exploited, a Nuclei template exists, and there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 14.2.32CPE matchmatch criteria | cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:* | ||
>= 15.0.0, < 15.4.7CPE matchmatch criteria | cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.