high85%
Forwarded Server Actions expose internal origin (localhost:PORT) via headers()
When a Server Action is forwarded to a worker that does not contain the action in its bundle, Next.js performs an internal HTTP fetch to `__NEXT_PRIVATE_ORIGIN` (http://localhost:PORT). This causes the forwarded subrequest's `Host` header to be derived from the URL, so `headers().get('host')` inside the action returns `localhost:PORT` instead of the original request's host. Self-hosted multi-tenant applications that resolve tenants from the `host` header break specifically for forwarded actions.
