Authorization Bypass in Next.js Middleware
100Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 9.1epss 99%
from disclosure to weapon1 days
Published on NVDMar 21
1st PoC+1d
metasploitMar 21
VulnCheck+7d
exploitation probability
99%top 1% of all CVEs
observed exploitation
yesVulnCheck
203 public exploit(s)
In short
Next.js versions 1.11.4 through 15.2.2 allow attackers to bypass authorization checks implemented in middleware by manipulating the x-middleware-subrequest header, potentially granting unauthorized access to protected resources.
Technical detail
Authorization bypass in Next.js middleware occurs when an attacker crafts requests with a spoofed x-middleware-subrequest header, causing the authorization logic to be skipped or misinterpreted. This affects versions 1.11.4 to 15.2.2; the vulnerability is patched in 12.3.5, 13.5.9, 14.2.25, and 15.2.3. The attack requires network access to the application and results in circumvention of authorization controls.
Summary generated and translated by AI from the official description.
Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware. If patching to a safe version is infeasible, it is recommend that you prevent external user requests which contain the x-middleware-subrequest header from reaching your Next.js application. This vulnerability is fixed in 12.3.5, 13.5.9, 14.2.25, and 15.2.3.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
vercel · next.jspublic PoCs found — 203
exploitdbwww.exploit-db.com/exploits/52124unverifiedgithubgithub.com/aydinnyunus/CVE-2025-29927★ 101githubgithub.com/AnonKryptiQuz/NextSploit★ 92githubgithub.com/websecnl/CVE-2025-29927-PoC-Exploit★ 20githubgithub.com/6mile/nextjs-CVE-2025-29927★ 19githubgithub.com/azu/nextjs-cve-2025-29927-poc★ 15githubgithub.com/lirantal/vulnerable-nextjs-14-CVE-2025-29927★ 14githubgithub.com/UNICORDev/exploit-CVE-2025-29927★ 12githubgithub.com/MuhammadWaseem29/CVE-2025-29927-POC★ 9githubgithub.com/phoscoder/ghost-route★ 9githubgithub.com/kOaDT/poc-cve-2025-29927★ 8githubgithub.com/gotr00t0day/CVE-2025-29927★ 8githubgithub.com/KaztoRay/CVE-2025-29927-Research★ 7githubgithub.com/strobes-security/nextjs-vulnerable-app★ 6githubgithub.com/alihussainzada/CVE-2025-29927-PoC★ 5githubgithub.com/fourcube/nextjs-middleware-bypass-demo★ 5githubgithub.com/HoumanPashaei/CVE-2025-29927★ 5githubgithub.com/RoyCampos/CVE-2025-29927★ 4githubgithub.com/t3tra-dev/cve-2025-29927-demo★ 4githubgithub.com/Ademking/CVE-2025-29927★ 4githubgithub.com/c0dejump/CVE-2025-29927-check★ 3githubgithub.com/luq0x/0xMiddleware★ 3githubgithub.com/0xWhoknows/CVE-2025-29927★ 3githubgithub.com/Eve-SatOrU/POC-CVE-2025-29927★ 3githubgithub.com/pouriam23/Next.js-Middleware-Bypass-CVE-2025-29927-★ 2githubgithub.com/TheresAFewConors/CVE-2025-29927-Testing★ 2githubgithub.com/emadshanab/CVE-2025-29927★ 2githubgithub.com/nicknisi/next-attack★ 2githubgithub.com/Oyst3r1ng/CVE-2025-29927★ 2githubgithub.com/Nekicj/CVE-2025-29927-exploit★ 2githubgithub.com/lem0n817/CVE-2025-29927★ 2githubgithub.com/jmbowes/NextSecureScan★ 2githubgithub.com/EQSTLab/CVE-2025-29927★ 2githubgithub.com/ferpalma21/Automated-Next.js-Security-Scanner-for-CVE-2025-29927★ 2githubgithub.com/lstudlo/nextjs-cve-demo★ 2githubgithub.com/arvion-agent/next-CVE-2025-29927★ 2githubgithub.com/kh4sh3i/CVE-2025-29927★ 2githubgithub.com/iteride/CVE-2025-29927★ 1githubgithub.com/alastair66/CVE-2025-29927★ 1githubgithub.com/pixilated730/NextJS-Exploit-★ 1githubgithub.com/0xnxt1me/CVE-2025-29927★ 1githubgithub.com/mhamzakhattak/CVE-2025-29927★ 1githubgithub.com/rubbxalc/CVE-2025-29927★ 1githubgithub.com/sermikr0/nextjs-middleware-auth-bypass★ 1githubgithub.com/Bongni/CVE-2025-29927★ 1githubgithub.com/liamromanis101/CVE-2025-29927-NextJS★ 1githubgithub.com/DanielHallbro/CVE-2025-29927-Nextjs-Bypass-PoC★ 1githubgithub.com/Kamal-418/Vulnerable-Lab-NextJS-CVE-2025-29927★ 1githubgithub.com/olimpiofreitas/CVE-2025-29927-scanner★ 1githubgithub.com/moften/CVE-2025-29927_Next.js_Auth_Bypass★ 1githubgithub.com/kazuya256/next-js-auth-bypass★ 1githubgithub.com/berraesen/nextjs-middleware-auth-bypass-lab★ 1githubgithub.com/kuzushiki/CVE-2025-29927-test★ 1githubgithub.com/ricsirigu/CVE-2025-29927★ 1githubgithub.com/yugo-eliatrope/test-cve-2025-29927★ 1githubgithub.com/m2hcz/PoC-for-Next.js-Middleware★ 1githubgithub.com/nocomp/CVE-2025-29927-scanner★ 1githubgithub.com/w2hcorp/CVE-2025-29927-PoC★ 1githubgithub.com/fahimalshihab/NextBypass★ 0githubgithub.com/Balajih4kr/cve-2025-29927★ 0githubgithub.com/YEONDG/nextjs-cve-2025-29927★ 0githubgithub.com/ethanol1310/POC-CVE-2025-29927-★ 0githubgithub.com/bk-security/auth-header-trust-rules★ 0githubgithub.com/Grand-Moomin/Vuln-Next.js-CVE-2025-29927★ 0githubgithub.com/aleongx/CVE-2025-29927_Scanner★ 0githubgithub.com/ValGrace/middleware-auth-bypass★ 0githubgithub.com/amitlttwo/Next.JS-CVE-2025-29927★ 0githubgithub.com/0xb1lal/CVE-2025-29927★ 0githubgithub.com/mickhacking/Thank-u-Next★ 0githubgithub.com/b4sh0xf/PoC-CVE-2025-29927★ 0githubgithub.com/rgvillanueva28/vulnbox-easy-CVE-2025-29927★ 0githubgithub.com/s11s11/CVE-2025-29927★ 0githubgithub.com/MKIRAHMET/CVE-2025-29927-PoC★ 0githubgithub.com/metasploit403/cve-2025-29927-lab★ 0githubgithub.com/shahin-shadow/nextjs-auth-bypass★ 0githubgithub.com/dante01yoon/CVE-2025-29927★ 0githubgithub.com/Nayekah/Next.js-Proof-of-Concept★ 0githubgithub.com/TheWaterbug/alpr-dashboard-patches★ 0githubgithub.com/all3njk/NextJS_CVE-2025-29927★ 0githubgithub.com/Toddkk02/CVE-2025-29927★ 0githubgithub.com/sangrok-jeon/CVE-2025-29927-Nextjs-Analysis★ 0githubgithub.com/Si-Ni/CVE-2025-29927-Proof-of-Concept★ 0githubgithub.com/kuyrathdaro/cve-2025-29927★ 0githubgithub.com/iSee857/CVE-2025-29927★ 0githubgithub.com/amalpvatayam67/day10-nextjs-middleware-lab★ 0githubgithub.com/dedibagus/cve-2025-29927-poc★ 0githubgithub.com/sdrtba/CVE-2025-29927★ 0githubgithub.com/Heimd411/CVE-2025-29927-PoC★ 0githubgithub.com/serhalp/test-cve-2025-29927★ 0githubgithub.com/adjscent/vulnerable-nextjs-14-CVE-2025-29927★ 0githubgithub.com/zs1n/CVE-2025-29927★ 0githubgithub.com/R3verseIN/Nextjs-middleware-vulnerable-appdemo-CVE-2025-29927★ 0githubgithub.com/sahbaazansari/CVE-2025-29927★ 0githubgithub.com/sn1p3rt3s7/NextJS_CVE-2025-29927★ 0githubgithub.com/hujiaozhuzhu/CVE-2025-29927__Next.js★ 0githubgithub.com/SugiB3o/vulnerable-nextjs-14-CVE-2025-29927★ 0githubgithub.com/sagsooz/CVE-2025-29927★ 0githubgithub.com/enochgitgamefied/NextJS-CVE-2025-29927-Docker-Lab★ 0githubgithub.com/JOOJIII/CVE-2025-29927★ 0githubgithub.com/elshaheedy/CVE-2025-29927-Sigma-Rule★ 0githubgithub.com/furmak331/CVE-2025-29927★ 0githubgithub.com/EarthAngel666/x-middleware-exploit★ 0githubgithub.com/Hirainsingadia/CVE-2025-29927★ 0githubgithub.com/enochgitgamefied/NextJS-CVE-2025-29927★ 0githubgithub.com/0xPThree/next.js_cve-2025-29927★ 0githubgithub.com/0xcucumbersalad/cve-2025-29927★ 0githubgithub.com/maronnjapan/claude-create-CVE-2025-29927★ 0githubgithub.com/Knotsecurity/CVE-2025-29927-NextJs-Middleware-Simulation★ 0githubgithub.com/ayato-shitomi/WebLab_CVE-2025-29927★ 0githubgithub.com/darklotuskdb/nextjs-CVE-2025-29927-hunter★ 0githubgithub.com/w3shinew/CVE-2025-29927★ 0githubgithub.com/aleongx/CVE-2025-29927★ 0githubgithub.com/l1uk/nextjs-middleware-exploit★ 0githubgithub.com/ticofookfook/poc-nextjs-CVE-2025-29927★ 0githubgithub.com/Fomovet/cve-2025-29927★ 0githubgithub.com/SwapnilDeshpande/cve-2025-29927-lab★ 0githubgithub.com/0xPb1/Next.js-CVE-2025-29927★ 0githubgithub.com/jeymo092/cve-2025-29927★ 0githubgithub.com/gitgudKrish/cve-2025-29927-nextjs★ 0githubgithub.com/yuzu-juice/CVE-2025-29927_demo★ 0githubgithub.com/pickovven/vulnerable-nextjs-14-CVE-2025-29927★ 0githubgithub.com/Ev3rPalestine/0xMiddleware★ 0githubgithub.com/Naveen-005/Next.Js-middleware-bypass-vulnerability-CVE-2025-29927★ 0githubgithub.com/Gokul-Krishnan-V-R/cve-2025-29927★ 0vulncheckvulncheck.com/xdb/146954f9a57bunverifiedvulncheckvulncheck.com/xdb/c6f0f626a500unverifiedvulncheckvulncheck.com/xdb/bf3470ff5f46unverifiedvulncheckvulncheck.com/xdb/149c2c7884b8unverifiedvulncheckvulncheck.com/xdb/70ec8fa6e178unverifiedvulncheckvulncheck.com/xdb/c3ce0f4afc74unverifiedvulncheckvulncheck.com/xdb/834958d12e1funverifiedvulncheckvulncheck.com/xdb/599cc28d6377unverifiedvulncheckvulncheck.com/xdb/b0aa5a26c434unverifiedvulncheckvulncheck.com/xdb/c304b1a61e0cunverifiedvulncheckvulncheck.com/xdb/bbc953c25fe5unverifiedvulncheckvulncheck.com/xdb/931872df3f05unverifiedvulncheckvulncheck.com/xdb/b9a379395734unverifiedvulncheckvulncheck.com/xdb/ab0e059bad2cunverifiedvulncheckvulncheck.com/xdb/15449124c3f3unverifiedvulncheckvulncheck.com/xdb/161e4016ef9eunverifiedvulncheckvulncheck.com/xdb/8338d5de007funverifiedvulncheckvulncheck.com/xdb/bad0b9008b82unverifiedvulncheckvulncheck.com/xdb/4457ba8b735dunverifiedvulncheckvulncheck.com/xdb/606f485ea796unverifiedvulncheckvulncheck.com/xdb/9ccf7c3e3476unverifiedvulncheckvulncheck.com/xdb/7e64c0d5c958unverifiedvulncheckvulncheck.com/xdb/9931bf17ce9aunverifiedvulncheckvulncheck.com/xdb/9aadecca48ffunverifiedvulncheckvulncheck.com/xdb/3c33a028a389unverifiedvulncheckvulncheck.com/xdb/ccac829868e2unverifiedvulncheckvulncheck.com/xdb/9d84264cafc0unverifiedvulncheckvulncheck.com/xdb/ce17fda5ea0eunverifiedvulncheckvulncheck.com/xdb/b7ffa9af4976unverifiedvulncheckvulncheck.com/xdb/732e92c77220unverifiedvulncheckvulncheck.com/xdb/4f01ab59fadfunverifiedvulncheckvulncheck.com/xdb/642931d86f5funverifiedvulncheckvulncheck.com/xdb/e9ede2cc0a98unverifiedvulncheckvulncheck.com/xdb/196261a4b887unverifiedvulncheckvulncheck.com/xdb/856f20417ec0unverifiedvulncheckvulncheck.com/xdb/88a2d7e481d9unverifiedvulncheckvulncheck.com/xdb/769acb348f7eunverifiedvulncheckvulncheck.com/xdb/96b8eb3071fbunverifiedvulncheckvulncheck.com/xdb/a20d9d4a3ef9unverifiedvulncheckvulncheck.com/xdb/d93f8e59e988unverifiedvulncheckvulncheck.com/xdb/668ba5374c71unverifiedvulncheckvulncheck.com/xdb/11e310f64af2unverifiedvulncheckvulncheck.com/xdb/cedd4e3465cfunverifiedvulncheckvulncheck.com/xdb/f732acfcd062unverifiedvulncheckvulncheck.com/xdb/31fd912112fdunverifiedvulncheckvulncheck.com/xdb/ab366bce935dunverifiedvulncheckvulncheck.com/xdb/c468779ec72eunverifiedvulncheckvulncheck.com/xdb/1f968bf8ddb5unverifiedvulncheckvulncheck.com/xdb/e37333645d67unverifiedvulncheckvulncheck.com/xdb/d6c298b7c335unverifiedvulncheckvulncheck.com/xdb/048bbb1c3879unverifiedvulncheckvulncheck.com/xdb/fb68243cf5d9unverifiedvulncheckvulncheck.com/xdb/55eed4b0a007unverifiedvulncheckvulncheck.com/xdb/84b3af5e5b8cunverifiedvulncheckvulncheck.com/xdb/57cace7e403eunverifiedvulncheckvulncheck.com/xdb/3a29262152caunverifiedvulncheckvulncheck.com/xdb/4b0c834e9af7unverifiedvulncheckvulncheck.com/xdb/4f3380b18331unverifiedvulncheckvulncheck.com/xdb/00d1f162e925unverifiedvulncheckvulncheck.com/xdb/2f1add429d71unverifiedvulncheckvulncheck.com/xdb/5b54fe2278e7unverifiedvulncheckvulncheck.com/xdb/0a05dba55328unverifiedvulncheckvulncheck.com/xdb/62f5549bcc02unverifiedvulncheckvulncheck.com/xdb/879c5a216a90unverifiedvulncheckvulncheck.com/xdb/34222b91858funverifiedvulncheckvulncheck.com/xdb/b8d9fccc13ccunverifiedvulncheckvulncheck.com/xdb/e1b5b7034d46unverifiedvulncheckvulncheck.com/xdb/3ae98ccea97dunverifiedvulncheckvulncheck.com/xdb/2a7e1b337763unverifiedvulncheckvulncheck.com/xdb/a4a24567290funverifiedvulncheckvulncheck.com/xdb/441991ddd347unverifiedvulncheckvulncheck.com/xdb/4e891336892eunverifiedvulncheckvulncheck.com/xdb/56769ea6f72dunverifiedvulncheckvulncheck.com/xdb/357690cfa2e3unverifiedvulncheckvulncheck.com/xdb/39a990390c28unverifiedvulncheckvulncheck.com/xdb/70ed1f6be6fbunverifiedvulncheckvulncheck.com/xdb/ebf20b63ad14unverifiedvulncheckvulncheck.com/xdb/751d55c8e070unverifiedvulncheckvulncheck.com/xdb/7bfe846f0256unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://github.com/vercel/next.js/commit/52a078da3884efe6501613c7834a3d02a91676d2https://github.com/vercel/next.js/commit/5fd3ae8f8542677c6294f32d18022731eab6fe48https://github.com/vercel/next.js/releases/tag/v12.3.5https://github.com/vercel/next.js/releases/tag/v13.5.9https://github.com/vercel/next.js/security/advisories/GHSA-f82v-jwr5-mffwhttps://security.netapp.com/advisory/ntap-20250328-0002/http://www.openwall.com/lists/oss-security/2025/03/23/3http://www.openwall.com/lists/oss-security/2025/03/23/4