← Back to CVE List
Vulnerability Intelligence Report
Authorization Bypass in Next.js Middleware

CVE-2025-29927

Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware. If patching to a safe version is infeasible, it is recommend that you prevent external user requests which contain the x-middleware-subrequest header from reaching your Next.js application. This vulnerability is fixed in 12.3.5, 13.5.9, 14.2.25, and 15.2.3.

Nuclei Template
CVSS Base Score
9.1
CRITICAL
Exploitability:3.9
Impact Score:5.2
EPSS Probability:99.62%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-285 ↗CWE-285: Improper Authorization

Affected Products & Versions

Vendor Product Affected Versions
vercel next.js >= 11.1.4, < 12.3.5 (affected), >= 14.0.0, < 14.2.25 (affected), >= 15.0.0, < 15.2.3 (affected), >= 13.0.0, < 13.5.9 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Nuclei Template
SCANNER AVAILABLE
EPSS Score
99.621%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2025-03-12T13:42:22
Published2025-03-21T14:34:49
Last Updated2025-04-08T15:17:05

LINK COPIED TO CLIPBOARD