CyberICT

CVE-2025-29927

Vercel · Published March 21, 2025

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

Next.js middleware authorization bypass. Sending a request with x-middleware-subrequest header set to the middleware's module path allows attackers to skip middleware execution entirely, bypassing authentication and authorization controls.

Affected Products

  • Next.js >= 11.1.4 and < 14.2.25
  • Next.js >= 15.0.0 and < 15.2.3

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Related Advisories