CVE-2025-29927: Next.js Middleware Flaw
ID: c0bf0d49-47f0-5ee7-b905-bd296c4e7ce3
STIX ID: report--c0bf0d49-47f0-5ee7-b905-bd296c4e7ce3
Feed Name: Zscaler Security Research Blog
Threat Score
This report describes CVE-2025-29927: an authorization bypass in Next.js Middleware where the runMiddleware function trusts and parses the x-middleware-subrequest header, allowing attackers to craft header values (including repeated entries) that bypass middleware checks and gain unauthorized access; the issue is addressed by stripping internal headers and validating the header value against a random hexadecimal string in the patch included in Next.js 15.2.3.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
