CVE-2024-34351
Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server Actions. If the `Host` header is modified, and the below conditions are also met, an attacker may be able to make requests that appear to be originating from the Next.js application server itself. The required conditions are 1) Next.js is running in a self-hosted manner; 2) the Next.js application makes use of Server Actions; and 3) the Server Action performs a redirect to a relative path which starts with a `/`. This vulnerability was fixed in Next.js `14.1.1`.
EPSS 92.75% · 99.8th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| vercel | next.js | 13.4.0, 13.4.0, * |
| vercel | next.js | 13.4.0 |
| npm | next | 13.4.0, 13.4.0 |
Timeline
- Jan 21, 1970 Security Advisory
- May 9, 2024 CVE Published
- May 10, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 31, 2024 Coalition ESS Score
- Mar 17, 2025 EPSS Score
- Mar 23, 2025 EPSS Score
- Mar 24, 2025 EPSS Score
- Mar 27, 2025 EPSS Score
- Mar 28, 2025 EPSS Score
- Mar 29, 2025 EPSS Score
- Mar 30, 2025 EPSS Score
References
- https://github.com/vercel/next.js/security/advisories/GHSA-fr5h-rqp8-mj6g url
- https://github.com/vercel/next.js/pull/62561 url
- https://github.com/vercel/next.js/commit/8f7a6ca7d21a97bc9f7a1bbe10427b5ad74b9085 url
- https://www.ibm.com/support/pages/node/7158042 advisory
- https://www.ibm.com/support/pages/node/7157662 advisory
- https://www.ibm.com/support/pages/node/7157750 advisory
- https://www.ibm.com/support/pages/node/7157924 advisory
- https://www.ibm.com/support/pages/node/7157753 advisory
- https://www.ibm.com/support/pages/node/7157847 advisory
- https://www.ibm.com/support/pages/node/7157927 advisory
- https://www.ibm.com/support/pages/node/7157929 advisory
- https://www.ibm.com/support/pages/node/7176657 advisory
- https://www.ibm.com/support/pages/node/7176642 advisory
- https://www.ibm.com/support/pages/node/7176660 advisory
- https://www.ibm.com/support/pages/node/7176201 advisory
- https://www.ibm.com/support/pages/node/7176391 advisory
- https://www.ibm.com/support/pages/node/7176392 advisory
- https://www.ibm.com/support/pages/node/7176386 advisory
- https://www.ibm.com/support/pages/node/7176389 advisory
- https://www.ibm.com/support/pages/node/7176451 advisory
…and 4 more