CVE-2025-30218 | vercel next.js 12.3.5/13.5.9/14.2.25/15.2.3 x-middleware-subrequest-id information disclosure (GHSA-223j-4rm8-mrmf)
A vulnerability classified as problematic has been found in vercel next.js 12.3.5/13.5.9/14.2.25/15.2.3. Affected is an unknown function. The manipulation of the argument x-middleware-subrequest-id leads to information disclosure.
This vulnerability is traded as CVE-2025-30218. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.