logo

Next.js Middleware Vulnerability (CVE-2025-29927): What You Need to Know and How to Respond

ID: 4c891089-f099-59cc-94fe-1191b57567a3

STIX ID: report--4c891089-f099-59cc-94fe-1191b57567a3

Feed Name: SOCRadar Blog

Threat Score
80/100

Date Published: 2025-03-24

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

**Executive summary:** A critical Next.js middleware authorization-bypass (CVE-2025-29927, CVSS 9.1) lets attackers skip middleware-based access controls by using crafted x-middleware-subrequest headers; it affects Next.js 11.1.4 through 13.5.6 and unpatched 14.x/15.x installations, with patches released for 14.2.25+ and 15.2.3+, and the advisory urges immediate upgrades, logging/monitoring, and edge/proxy header blocking as temporary mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.