CVE-2025-29927 is a critical authorization bypass vulnerability affecting Next.js versions 1.11.4 up to 12.3.5, 13.5.9, 14.2.25, and 15.2.3, allowing attackers to circumvent security checks within Next.js middleware. With a CVSS score of 9.1 (CRITICAL), this vulnerability is easily exploitable over the network without authentication, leading to high impact on confidentiality and integrity. Active exploitation has been observed, with exploit code publicly available via Nuclei templates and ExploitDB, and significant community discussion and media coverage highlight its widespread threat. Organizations are strongly advised to patch immediately or implement the recommended mitigation of blocking requests containing the x-middleware-subrequest header.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.1.4, < 12.3.5CPE matchmatch criteria | cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:* | ||
>= 13.0.0, < 13.5.9CPE matchmatch criteria | cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:* | ||
>= 14.0.0, < 14.2.25CPE matchmatch criteria | cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:* | ||
>= 15.0.0, < 15.2.3CPE matchmatch criteria | cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.