logo

Understanding CVE-2025-29927: The Next.js Middleware Authorization Bypass Vulnerability

ID: 8ec2db27-caef-583a-afd5-a1443d26cc7e

STIX ID: report--8ec2db27-caef-583a-afd5-a1443d26cc7e

Feed Name: Datadog Security Labs

Threat Score
75/100

Date Published: 2025-03-28

Date Updated: 2026-04-27

...
...

Datadog Security Research published an advisory for CVE-2025-29927, a Next.js middleware authorization bypass that lets attackers supply a crafted x-middleware-subrequest header to skip middleware security checks and access protected routes; the advisory lists affected Next.js versions, proof-of-concept details and remediation (upgrade or drop the header), and includes observed scanner IPs and User-Agent indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.