logo

Critical flaw in Next.js lets hackers bypass authorization

ID: 5c57cfc9-f4eb-5329-b480-f2cca7c4572b

STIX ID: report--5c57cfc9-f4eb-5329-b480-f2cca7c4572b

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-03-24

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical authorization-bypass vulnerability (CVE-2025-29927) was disclosed in Next.js where an attacker-supplied 'x-middleware-subrequest' header can skip middleware execution and bypass authentication/authorization checks; affected versions are all releases before 15.2.3, 14.2.25, 13.5.9, and 12.3.5 for self-hosted apps using 'next start' with 'output:standalone'. Researchers published technical details and the advisory warns that Vercel/Netlify-hosted apps and static exports are not impacted; mitigations include upgrading to patched releases or blocking external requests with the header.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.