Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p9j2-gv94-2wf4

Опубликовано: 22 июл. 2026
Источник: github
Github: Прошло ревью
CVSS4: 8.3

Описание

Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname

Impact

A rewrites() or redirects() rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A redirects() rule configured this way is vulnerable to an Open Redirect.

This affects any destination that puts a dynamic segment in the hostname, whether from the path:

// next.config.js module.exports = { async rewrites() { return [ { source: '/:tenant', destination: 'https://:tenant.api.example.com', }, ] }, }

or from a has capture:

// next.config.js module.exports = { async rewrites() { return [ { source: '/', has: [{ type: 'query', key: 'region', value: '(?<region>.+)' }], destination: 'https://:region.api.example.com', }, ] }, }

Workarounds

If you cannot upgrade immediately, do not build the hostname of an external rewrites() or redirects() destination from user-controlled input. If a dynamic subdomain is required, constrain the value to hostname-safe characters: value: '(?<region>[a-z0-9-]+)'.

Пакеты

Наименование

next

npm
Затронутые версииВерсия исправления

>= 12.0.0, < 15.5.21

15.5.21

Наименование

next

npm
Затронутые версииВерсия исправления

>= 16.0.0, < 16.2.11

16.2.11

EPSS

Процентиль: 48%
0.00653
Низкий

8.3 High

CVSS4

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.2
redhat
5 дней назад

A flaw was found in Next.js, a React framework for building web applications. This vulnerability allows a remote attacker to perform Server-Side Request Forgery (SSRF) or Open Redirect attacks. When a `rewrites()` or `redirects()` rule constructs an external destination hostname using attacker-controlled input, the application can be coerced into proxying requests to arbitrary hosts, leading to SSRF. Additionally, this misconfiguration can result in Open Redirects, potentially exposing users to phishing.

CVSS3: 6.1
nvd
5 дней назад

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A redirects() rule configured this way is vulnerable to an Open Redirect. This issue has been fixed in versions 15.5.21 and 16.2.11.

EPSS

Процентиль: 48%
0.00653
Низкий

8.3 High

CVSS4

Дефекты

CWE-918