logo

CVE-2025-29927: Next.js Middleware Flaw

ID: c0bf0d49-47f0-5ee7-b905-bd296c4e7ce3

STIX ID: report--c0bf0d49-47f0-5ee7-b905-bd296c4e7ce3

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-05-22

Date Updated: 2026-05-01

...
...

This report describes CVE-2025-29927: an authorization bypass in Next.js Middleware where the runMiddleware function trusts and parses the x-middleware-subrequest header, allowing attackers to craft header values (including repeated entries) that bypass middleware checks and gain unauthorized access; the issue is addressed by stripping internal headers and validating the header value against a random hexadecimal string in the patch included in Next.js 15.2.3.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.