logo

Researchers raise alarm about critical Next.js vulnerability

ID: b2db2f21-c3d5-5d52-b640-8da02e770263

STIX ID: report--b2db2f21-c3d5-5d52-b640-8da02e770263

Feed Name: CyberScoop

Threat Score
70/100

Date Published: 2025-03-24

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

Researchers disclosed a critical Next.js vulnerability (CVE-2025-29927, CVSS 9.1) that can bypass middleware authorization and enable content security bypass and cache poisoning; Vercel issued a patch (Next.js 15.2.3) and published advisory materials in March, and while no active exploitation has been reported, self-hosted Next.js applications using middleware remain at risk until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.