Server-Side Request Forgery (SSRF) in Next.js - CVE-2025-57822

 

Server-Side Request Forgery (SSRF) in Next.js - CVE-2025-57822

Published: August 30, 2025


Vulnerability identifier: #VU114571
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2025-57822
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input when next() is used without explicitly passing the request object. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.

Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.


Affected software

Next.js
IBM Security QRadar Network Threat Analytics
QRadar Pre-Validation App
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
WatsonX BI Assistant
Maximo Application Suite - Edge Data Collector
User Entity Behavior Analytics
IBM Security QRadar Analyst Workflow

How to mitigate CVE-2025-57822

Install updates from vendor's website.

Next.js - addressed in versions 14.2.32, 15.4.7
IBM Security QRadar Network Threat Analytics - update to 1.4.2
QRadar Pre-Validation App - update to 2.0.2
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2.2
WatsonX BI Assistant - update to 5.2.2
Maximo Application Suite - Edge Data Collector - addressed in versions 8.11.21, 9.0.13, 9.1.3
IBM Security QRadar Analyst Workflow - update to 3.0.1
User Entity Behavior Analytics - update to 5.0.2

External References

Related Security Bulletins