Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware. If patching to a safe version is infeasible, it is recommend that you prevent external user requests which contain the x-middleware-subrequest header from reaching your Next.js application. This vulnerability is fixed in 12.3.5, 13.5.9, 14.2.25, and 15.2.3.
https://www.securityweek.com/pcpjack-worm-removes-teampcp-infections-steals-credentials/
https://thehackernews.com/2026/05/pcpjack-credential-stealer-exploits-5.html
https://thehackernews.com/2026/02/teampcp-worm-exploits-cloud.html
https://thehackernews.com/2025/12/react2shell-vulnerability-actively.html
https://thehackernews.com/2025/03/cisa-flags-two-six-year-old-sitecore.html
https://www.securityweek.com/critical-next-js-vulnerability-in-hacker-crosshairs/
https://socket.dev/blog/nextjs-moves-to-scheduled-security-releases
https://snyk.io/blog/qinglong-task-scheduler-rce-vulnerabilities/
https://hackread.com/next-js-middleware-flaw-bypass-authorization/
https://thehackernews.com/2025/03/critical-nextjs-vulnerability-allows.html
https://securityaffairs.com/175775/security/next-js-react-framework-critical-issue.html
https://github.com/Vaibhav91one/nextjs-cve-lab
https://github.com/berraesen/nextjs-middleware-auth-bypass-lab
https://github.com/shunfeng8421/exploit-library
https://github.com/diedromeo/CVE-Labs-2025-2026
https://github.com/shunfeng8421/security-audit
https://github.com/falc0n-researcher/depfuse-oss
https://github.com/kenlacroix/palisade
https://github.com/SwapnilDeshpande/cve-2025-29927-lab
https://github.com/Nan-Hack-371/Intern-in-Vulncure
https://github.com/sonnycroco/HTB-Reactor-Linux-Machine---Walkthrough
https://github.com/1392081456/sigma-detection-rules
https://github.com/bk-security/auth-header-trust-rules
https://github.com/ODamDam/sec-report-kit
https://github.com/ChovTheHacker/EREBUS
https://github.com/dbwlsdnr95/CVE-Research
https://github.com/Nayekah/Next.js-Proof-of-Concept
https://github.com/TheWaterbug/alpr-dashboard-patches
https://github.com/kdairatchi/nuclei-templates-custom
https://github.com/shahin-shadow/nextjs-auth-bypass
https://github.com/metasploit403/cve-2025-29927-lab
https://github.com/Noumenon-ai/cve-guard
https://github.com/Su1ph3r/vercelsior
https://github.com/EvanThomasLuke/HACK-AGI-CONTAINERS
https://github.com/thecosmicexplorer/tools
https://github.com/dbwlsdnr95/CVE-2025-29927
https://github.com/cristiancolon/ThreatWarden
https://github.com/ShubhamDubeyy/Aurex
https://github.com/Si-Ni/CVE-2025-29927-Proof-of-Concept
https://github.com/Shibly6/vulnerability-labs
https://github.com/N3k0t-dev/bughunter-cyber-intel-dashboard
https://github.com/fbettag/bluedragon-web-security
https://github.com/tonythebughunter/CVEs
https://github.com/hlsitechio/shellockolm
https://github.com/hlsitechio/Shellockolm-AI-CLI-MCP-Scanner
https://github.com/BugHawak/CVE-2025-29927
https://github.com/NS-Projects-Unina/CTF_CVE_DSP_1
https://github.com/Jenderal92/PoC-AutoSync
https://github.com/diogolourencodev/CVEs
https://github.com/V0idA2tronaut/CVEs
https://github.com/Bongni/CVE-2025-29927
https://github.com/diogolourencodev/middleforce
https://github.com/amalpvatayam67/day10-nextjs-middleware-lab
https://github.com/sermikr0/nextjs-middleware-auth-bypass
https://github.com/NightfallSecDev/CVE
https://github.com/adjscent/vulnerable-nextjs-14-CVE-2025-29927
https://github.com/junwonheo/cve-analysis
https://github.com/a-s-m-asadujjaman/exploitables
https://github.com/Kamal-Hegazi/CVE-2025-29927-Next.js-Middleware-Authorization-Bypass
https://github.com/yembors64632/cve_monitor_Public
https://github.com/amitlttwo/Next.JS-CVE-2025-29927
https://github.com/TH-SecForge/CVE-2025-29972
https://github.com/B1ack4sh/Blackash-CVE-2025-29927
https://github.com/NickP3lle/llm4cve
https://github.com/huynguyen12536/CVE-2025-2995
https://github.com/SugiB3o/vulnerable-nextjs-14-CVE-2025-29927
https://github.com/sagsooz/CVE-2025-29927
https://github.com/enochgitgamefied/NextJS-CVE-2025-29927-Docker-Lab
https://github.com/lstudlo/nextjs-cve-demo
https://github.com/PuddinCat/GithubRepoSpider
https://github.com/EarthAngel666/x-middleware-exploit
https://github.com/olimpiofreitas/CVE-2025-29927_scanner
https://github.com/rubbxalc/CVE-2025-29927
https://github.com/HoumanPashaei/CVE-2025-29927
https://github.com/hed1ad/CVE-2025-29927
https://github.com/kh4sh3i/CVE-2025-29927
https://github.com/pouriam23/Next.js-Middleware-Bypass-CVE-2025-29927-
https://github.com/enochgitgamefied/NextJS-CVE-2025-29927
https://github.com/Knotsecurity/CVE-2025-29927-NextJs-Middleware-Simulation
https://github.com/UNICORDev/exploit-CVE-2025-29927
https://github.com/heqnx/cve-poc-mon
https://github.com/darklotuskdb/nextjs-CVE-2025-29927-hunter
https://github.com/pickovven/vulnerable-nextjs-14-CVE-2025-29927
https://github.com/pixilated730/NextJS-Exploit-
https://github.com/gotr00t0day/CVE-2025-29927
https://github.com/YEONDG/nextjs-cve-2025-29927
https://github.com/Balajih4kr/cve-2025-29927
https://github.com/fahimalshihab/NextBypass
https://github.com/nyctophile0969/CVE-2025-29927
https://github.com/BilalGns/CVE-2025-29927
https://github.com/alastair66/CVE-2025-29927
https://github.com/ayato-shitomi/WebLab_CVE-2025-29927
https://github.com/dante01yoon/CVE-2025-29927
https://github.com/ferpalma21/Automated-Next.js-Security-Scanner-for-CVE-2025-29927
https://github.com/AnonKryptiQuz/NextSploit
https://github.com/0x0Luk/0xMiddleware
https://github.com/nocomp/CVE-2025-29927-scanner
https://github.com/KaztoRay/CVE-2025-29927-Research
https://github.com/m2hcz/m2hcz-Next.js-security-flaw-CVE-2025-29927---PoC-exploit
https://github.com/Nekicj/CVE-2025-29927-exploit
https://github.com/aleongx/CVE-2025-29927_Scanner
https://github.com/jmbowes/NextSecureScan
https://github.com/nicknisi/next-attack
https://github.com/aleongx/CVE-2025-29927
https://github.com/Slvignesh05/CVE-2025-29927
https://github.com/narwalsguy/CVE-and-vuln-fixes
https://github.com/yugo-eliatrope/test-cve-2025-29927
https://github.com/maronnjapan/claude-create-CVE-2025-29927
https://github.com/c0dejump/CVE-2025-29927-check
https://github.com/ThemeHackers/CVE-2025-29972
https://github.com/0xcucumbersalad/cve-2025-29927
https://github.com/0xPThree/next.js_cve-2025-29927
https://github.com/TheresAFewConors/CVE-2025-29927-Testing
https://github.com/Jull3Hax0r/next.js-exploit
https://github.com/jeymo092/cve-2025-29927
https://github.com/takumade/ghost-route
https://github.com/elshaheedy/CVE-2025-29927-Sigma-Rule
https://github.com/momiroskik/nextjs-auth-bypass-cve-poc
https://github.com/tobiasGuta/CVE-2025-29927-POC
https://github.com/0xWhoknows/CVE-2025-29927
https://github.com/ricsirigu/CVE-2025-29927
https://github.com/kuzushiki/CVE-2025-29927-test
https://github.com/lem0n817/CVE-2025-29927
https://github.com/lediusa/CVE-2025-29927
https://github.com/arvion-agent/next-CVE-2025-29927
https://github.com/iSee857/CVE-2025-29927
https://github.com/fourcube/nextjs-middleware-bypass-demo
Published: 2025-03-21
Updated: 2025-09-10
Base Score: 9.4
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N
Severity: High
Base Score: 9.1
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity: Critical
EPSS: 0.99225
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Interest