logo

NCSC Urges Users to Patch Next.js Flaw Immediately

ID: 50290671-75b6-5da2-8b5d-4c88d7a2895a

STIX ID: report--50290671-75b6-5da2-8b5d-4c88d7a2895a

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2025-03-31

Date Updated: 2026-04-22

...
...

The UK NCSC warns of a critical authorization-bypass vulnerability (CVE-2025-29927) in Next.js that can allow external requests to skip middleware and authorization checks, potentially exposing sensitive data; maintainers released fixes for affected versions on March 22, proofs-of-concept are widely available, and mitigations include applying the fixed versions or blocking the x-middleware-subrequest header and monitoring logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.