Next.js Middleware Vulnerability (CVE-2025-29927): What You Need to Know and How to Respond
ID: 4c891089-f099-59cc-94fe-1191b57567a3
STIX ID: report--4c891089-f099-59cc-94fe-1191b57567a3
Feed Name: SOCRadar Blog
Threat Score
**Executive summary:** A critical Next.js middleware authorization-bypass (CVE-2025-29927, CVSS 9.1) lets attackers skip middleware-based access controls by using crafted x-middleware-subrequest headers; it affects Next.js 11.1.4 through 13.5.6 and unpatched 14.x/15.x installations, with patches released for 14.2.25+ and 15.2.3+, and the advisory urges immediate upgrades, logging/monitoring, and edge/proxy header blocking as temporary mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
