References https://nvd.nist.gov/vuln/detail/CVE-2025-57822 https://vercel.com/changelog/cve-2025-57822 https://github.com/vercel/next.js/security/advisories/GHSA-4342-x723-ch2f https://www.miggo.io/vulnerability-database/cve/CVE-2025-57822 https://security.snyk.io/vuln/SNYK-JS-NEXT-12299318 https://www.sentinelone.com/vulnerability-database/cve-2025-57822/ https://blog.rootsys.at/posts/nextjs-and-the-mutated-middleware/ https://www.intigriti.com/researchers/blog/hacking-tools/catflix-ctf-ssrf-nextjs-middleware https://cn-sec.com/archives/4450009.html https://cve.imfht.com/detail/CVE-2025-57822
Related VulnerabilitiesPoCCVE-2026-28141: NextGEN Gallery <= 4.2.3 - Reflected Cross-Site ScriptingPoCCVE-2026-29059: Windmill/Nextcloud Flow < 1.603.3 - Unauthenticated Path TraversalWindmill/Nextcloud Flow /api/w/_/jobs_u/get_log_file/ 目录遍历漏洞(CVE-2026-29059)Windmill/Nextcloud Flow /api/w/_/jobs_u/get_log_file/ 路径穿越漏洞PoCNext.js WebSocket 服务器端请求伪造漏洞(CVE-2026-44578)ERPNext /api/method/erpnext.stock.doctype.material_request.material_request.get_material_requests_based_on_supplier SQL 注入漏洞(CVE-2025-52039)ERPNext /api/method/erpnext.stock.doctype.stock_reconciliation.stock_reconciliation.get_stock_balance_for SQL 注入漏洞(CVE-2025-52041)ERPNext /api/method/erpnext.controllers.queries.get_blanket_orders SQL 注入漏洞(CVE-2025-52040)ERPNext /api/method/erpnext.buying.doctype.request_for_quotation.request_for_quotation.get_rfq_containing_supplier SQL 注入漏洞(CVE-2025-52042)ERPNext /api/method/erpnext.stock.utils.get_stock_balance SQL 注入漏洞(CVE-2025-52044)ERPNext /api/method/erpnext.accounts.doctype.chart_of_accounts_importer.chart_of_accounts_importer.import_coa SQL 注入漏洞(CVE-2025-52043)PandoraNext-TokensTool /api/selectSetting;login 权限绕过漏洞(CVE-2024-50641)