CVE-2025-29927

critical

Description

Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware. If patching to a safe version is infeasible, it is recommend that you prevent external user requests which contain the x-middleware-subrequest header from reaching your Next.js application. This vulnerability is fixed in 12.3.5, 13.5.9, 14.2.25, and 15.2.3.

References

https://github.com/Vaibhav91one/nextjs-cve-lab

https://github.com/berraesen/nextjs-middleware-auth-bypass-lab

https://github.com/shunfeng8421/exploit-library

https://github.com/diedromeo/CVE-Labs-2025-2026

https://github.com/shunfeng8421/security-audit

https://github.com/falc0n-researcher/depfuse-oss

https://github.com/kenlacroix/palisade

https://github.com/SwapnilDeshpande/cve-2025-29927-lab

https://github.com/Nan-Hack-371/Intern-in-Vulncure

https://github.com/sonnycroco/HTB-Reactor-Linux-Machine---Walkthrough

https://github.com/1392081456/sigma-detection-rules

https://github.com/bk-security/auth-header-trust-rules

https://github.com/ODamDam/sec-report-kit

https://github.com/ChovTheHacker/EREBUS

https://github.com/dbwlsdnr95/CVE-Research

https://github.com/Nayekah/Next.js-Proof-of-Concept

https://github.com/TheWaterbug/alpr-dashboard-patches

https://github.com/kdairatchi/nuclei-templates-custom

https://github.com/shahin-shadow/nextjs-auth-bypass

https://github.com/metasploit403/cve-2025-29927-lab

https://github.com/Noumenon-ai/cve-guard

https://github.com/Su1ph3r/vercelsior

https://github.com/EvanThomasLuke/HACK-AGI-CONTAINERS

https://github.com/thecosmicexplorer/tools

https://github.com/dbwlsdnr95/CVE-2025-29927

https://github.com/cristiancolon/ThreatWarden

https://github.com/ShubhamDubeyy/Aurex

https://github.com/Si-Ni/CVE-2025-29927-Proof-of-Concept

https://github.com/Shibly6/vulnerability-labs

https://github.com/N3k0t-dev/bughunter-cyber-intel-dashboard

https://github.com/fbettag/bluedragon-web-security

https://github.com/tonythebughunter/CVEs

https://github.com/hlsitechio/shellockolm

https://github.com/hlsitechio/Shellockolm-AI-CLI-MCP-Scanner

https://github.com/BugHawak/CVE-2025-29927

https://github.com/NS-Projects-Unina/CTF_CVE_DSP_1

https://github.com/Jenderal92/PoC-AutoSync

https://github.com/diogolourencodev/CVEs

https://github.com/V0idA2tronaut/CVEs

https://github.com/Bongni/CVE-2025-29927

https://github.com/diogolourencodev/middleforce

https://github.com/amalpvatayam67/day10-nextjs-middleware-lab

https://github.com/sermikr0/nextjs-middleware-auth-bypass

https://github.com/NightfallSecDev/CVE

https://github.com/adjscent/vulnerable-nextjs-14-CVE-2025-29927

https://github.com/junwonheo/cve-analysis

https://github.com/a-s-m-asadujjaman/exploitables

https://github.com/Kamal-Hegazi/CVE-2025-29927-Next.js-Middleware-Authorization-Bypass

https://github.com/yembors64632/cve_monitor_Public

https://github.com/amitlttwo/Next.JS-CVE-2025-29927

https://github.com/TH-SecForge/CVE-2025-29972

https://github.com/B1ack4sh/Blackash-CVE-2025-29927

https://github.com/NickP3lle/llm4cve

https://github.com/huynguyen12536/CVE-2025-2995

https://github.com/SugiB3o/vulnerable-nextjs-14-CVE-2025-29927

https://github.com/sagsooz/CVE-2025-29927

https://github.com/enochgitgamefied/NextJS-CVE-2025-29927-Docker-Lab

https://github.com/lstudlo/nextjs-cve-demo

https://github.com/PuddinCat/GithubRepoSpider

https://github.com/EarthAngel666/x-middleware-exploit

https://github.com/olimpiofreitas/CVE-2025-29927_scanner

https://github.com/rubbxalc/CVE-2025-29927

https://github.com/HoumanPashaei/CVE-2025-29927

https://github.com/hed1ad/CVE-2025-29927

https://github.com/kh4sh3i/CVE-2025-29927

https://github.com/pouriam23/Next.js-Middleware-Bypass-CVE-2025-29927-

https://github.com/enochgitgamefied/NextJS-CVE-2025-29927

https://github.com/Knotsecurity/CVE-2025-29927-NextJs-Middleware-Simulation

https://github.com/UNICORDev/exploit-CVE-2025-29927

https://github.com/heqnx/cve-poc-mon

https://github.com/darklotuskdb/nextjs-CVE-2025-29927-hunter

https://github.com/pickovven/vulnerable-nextjs-14-CVE-2025-29927

https://github.com/pixilated730/NextJS-Exploit-

https://github.com/gotr00t0day/CVE-2025-29927

https://github.com/YEONDG/nextjs-cve-2025-29927

https://github.com/Balajih4kr/cve-2025-29927

https://github.com/fahimalshihab/NextBypass

https://github.com/nyctophile0969/CVE-2025-29927

https://github.com/BilalGns/CVE-2025-29927

https://github.com/alastair66/CVE-2025-29927

https://github.com/ayato-shitomi/WebLab_CVE-2025-29927

https://github.com/dante01yoon/CVE-2025-29927

https://github.com/ferpalma21/Automated-Next.js-Security-Scanner-for-CVE-2025-29927

https://github.com/AnonKryptiQuz/NextSploit

https://github.com/0x0Luk/0xMiddleware

https://github.com/nocomp/CVE-2025-29927-scanner

https://github.com/KaztoRay/CVE-2025-29927-Research

https://github.com/m2hcz/m2hcz-Next.js-security-flaw-CVE-2025-29927---PoC-exploit

https://github.com/Nekicj/CVE-2025-29927-exploit

https://github.com/aleongx/CVE-2025-29927_Scanner

https://github.com/jmbowes/NextSecureScan

https://github.com/nicknisi/next-attack

https://github.com/aleongx/CVE-2025-29927

https://github.com/Slvignesh05/CVE-2025-29927

https://github.com/narwalsguy/CVE-and-vuln-fixes

https://github.com/yugo-eliatrope/test-cve-2025-29927

https://github.com/maronnjapan/claude-create-CVE-2025-29927

https://github.com/c0dejump/CVE-2025-29927-check

https://github.com/ThemeHackers/CVE-2025-29972

https://github.com/0xcucumbersalad/cve-2025-29927

https://github.com/0xPThree/next.js_cve-2025-29927

https://github.com/TheresAFewConors/CVE-2025-29927-Testing

https://github.com/Jull3Hax0r/next.js-exploit

https://github.com/jeymo092/cve-2025-29927

https://github.com/takumade/ghost-route

https://github.com/elshaheedy/CVE-2025-29927-Sigma-Rule

https://github.com/momiroskik/nextjs-auth-bypass-cve-poc

https://github.com/tobiasGuta/CVE-2025-29927-POC

https://github.com/0xWhoknows/CVE-2025-29927

https://github.com/ricsirigu/CVE-2025-29927

https://github.com/kuzushiki/CVE-2025-29927-test

https://github.com/lem0n817/CVE-2025-29927

https://github.com/lediusa/CVE-2025-29927

https://github.com/arvion-agent/next-CVE-2025-29927

https://github.com/iSee857/CVE-2025-29927

https://github.com/fourcube/nextjs-middleware-bypass-demo

https://github.com/RoyCampos/CVE-2025-29927

https://github.com/strobes-security/nextjs-vulnerable-app

Details

Source: Mitre, NVD

Published: 2025-03-21

Updated: 2025-09-10

Risk Information

CVSS v2

Base Score: 9.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

Severity: High

CVSS v3

Base Score: 9.1

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical

EPSS

EPSS: 0.99225

Vulnerability Watch

Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.

Vulnerability of Interest