Skip to content

arvion-agent/next-CVE-2025-29927

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

CVE-2025-29927: Authorization Bypass in Next.js Middleware

A critical vulnerability in Next.js (CVE-2025-29927) allows unauthorized access to protected routes by bypassing the middleware logic. The issue affects Next.js versions 11.1.4 to 13.5.6, and versions 14.x < 14.2.25 or 15.x < 15.2.3. To mitigate, upgrade to the latest fixed versions (14.2.25+ or 15.2.3+), or apply a firewall rule to block the x-middleware-subrequest header.

About

CVE-2025-29927 Authorization Bypass in Next.js Middleware

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors