logo

Behind the Middleware Curtain — Explaining CVE-2025-29927, A Critical Authorization Bypass in Next.js

ID: 3c7c9a71-e2a4-5093-b7b1-e017d3251546

STIX ID: report--3c7c9a71-e2a4-5093-b7b1-e017d3251546

Feed Name: Checkmarx Zero

Threat Score
90/100

Date Published: 2025-03-25

Date Updated: 2026-04-27

Author: Raphael Silva

...
...

This report documents CVE-2025-29927, a critical Next.js middleware authorization bypass in which attackers can set the x-middleware-subrequest header to cause the framework to skip middleware checks; it affects many Next.js versions, is trivial to exploit and likely to be automated, and is remediable by upgrading Next.js or blocking the header via WAF or server rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.