CVE-2025-30218 | vercel next.js 12.3.5/13.5.9/14.2.25/15.2.3 x-middleware-subrequest-id information disclosure (GHSA-223j-4rm8-mrmf)
A vulnerability marked as problematic has been reported in vercel next.js 12.3.5/13.5.9/14.2.25/15.2.3. Affected by this vulnerability is an unknown functionality. The manipulation of the argument x-middleware-subrequest-id leads to information disclosure.
This vulnerability is listed as CVE-2025-30218. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.