CVE-2025-29927
Vercel · Published March 21, 2025
9.1
CVSS v3.1
CRITICALPatch availableGet patch
Description
Next.js middleware authorization bypass. Sending a request with x-middleware-subrequest header set to the middleware's module path allows attackers to skip middleware execution entirely, bypassing authentication and authorization controls.
Affected Products
- Next.js >= 11.1.4 and < 14.2.25
- Next.js >= 15.0.0 and < 15.2.3
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N