Vulnerability Intelligence Report
Authorization Bypass in Next.js Middleware
CVE-2025-29927
Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware. If patching to a safe version is infeasible, it is recommend that you prevent external user requests which contain the x-middleware-subrequest header from reaching your Next.js application. This vulnerability is fixed in 12.3.5, 13.5.9, 14.2.25, and 15.2.3.
Nuclei Template
CVSS Base Score
9.1
CRITICAL
Exploitability:3.9
Impact Score:5.2
EPSS Probability:99.62%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-285 ↗CWE-285: Improper Authorization
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| vercel | next.js | >= 11.1.4, < 12.3.5 (affected), >= 14.0.0, < 14.2.25 (affected), >= 15.0.0, < 15.2.3 (affected), >= 13.0.0, < 13.5.9 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | GitHub, Inc. · Vendor · USA |
| Reserved | 2025-03-12T13:42:22 |
| Published | 2025-03-21T14:34:49 |
| Last Updated | 2025-04-08T15:17:05 |
Community Chatter & Buzz