← back
CVE-2025-29927criticalobserved exploitationCWE-285

Authorization Bypass in Next.js Middleware

100Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 9.1epss 99%
from disclosure to weapon1 days
Published on NVDMar 21
1st PoC+1d
metasploitMar 21
VulnCheck+7d
exploitation probability
99%top 1% of all CVEs
observed exploitation
yesVulnCheck
209 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Not affected
7 products (177 components) — because the vulnerable code is not present in the product
Red Hat Enterprise Linux 9 · Red Hat Enterprise Linux 8 · Red Hat Enterprise Linux 10 · Red Hat Enterprise Linux 7 · Red Hat Enterprise Linux AI (RHEL AI) · and others 2
In short

Next.js versions 1.11.4 through 15.2.2 allow attackers to bypass authorization checks implemented in middleware by manipulating the x-middleware-subrequest header, potentially granting unauthorized access to protected resources.

Technical detail

Authorization bypass in Next.js middleware occurs when an attacker crafts requests with a spoofed x-middleware-subrequest header, causing the authorization logic to be skipped or misinterpreted. This affects versions 1.11.4 to 15.2.2; the vulnerability is patched in 12.3.5, 13.5.9, 14.2.25, and 15.2.3. The attack requires network access to the application and results in circumvention of authorization controls.

Summary generated and translated by AI from the official description.
Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware. If patching to a safe version is infeasible, it is recommend that you prevent external user requests which contain the x-middleware-subrequest header from reaching your Next.js application. This vulnerability is fixed in 12.3.5, 13.5.9, 14.2.25, and 15.2.3.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
vercel · next.js
public PoCs found — 209
exploitdbwww.exploit-db.com/exploits/52124unverifiedgithubgithub.com/aydinnyunus/CVE-2025-29927★ 103githubgithub.com/AnonKryptiQuz/NextSploit★ 92githubgithub.com/websecnl/CVE-2025-29927-PoC-Exploit★ 20githubgithub.com/6mile/nextjs-CVE-2025-29927★ 19githubgithub.com/azu/nextjs-cve-2025-29927-poc★ 15githubgithub.com/lirantal/vulnerable-nextjs-14-CVE-2025-29927★ 14githubgithub.com/UNICORDev/exploit-CVE-2025-29927★ 14githubgithub.com/MuhammadWaseem29/CVE-2025-29927-POC★ 11githubgithub.com/phoscoder/ghost-route★ 9githubgithub.com/kOaDT/poc-cve-2025-29927★ 8githubgithub.com/gotr00t0day/CVE-2025-29927★ 8githubgithub.com/KaztoRay/CVE-2025-29927-Research★ 7githubgithub.com/alihussainzada/CVE-2025-29927-PoC★ 6githubgithub.com/strobes-security/nextjs-vulnerable-app★ 6githubgithub.com/HoumanPashaei/CVE-2025-29927★ 5githubgithub.com/fourcube/nextjs-middleware-bypass-demo★ 5githubgithub.com/t3tra-dev/cve-2025-29927-demo★ 4githubgithub.com/Ademking/CVE-2025-29927★ 4githubgithub.com/luq0x/0xMiddleware★ 3githubgithub.com/Eve-SatOrU/POC-CVE-2025-29927★ 3githubgithub.com/0xWhoknows/CVE-2025-29927★ 3githubgithub.com/c0dejump/CVE-2025-29927-check★ 3githubgithub.com/jmbowes/NextSecureScan★ 2githubgithub.com/lstudlo/nextjs-cve-demo★ 2githubgithub.com/EQSTLab/CVE-2025-29927★ 2githubgithub.com/emadshanab/CVE-2025-29927★ 2githubgithub.com/kh4sh3i/CVE-2025-29927★ 2githubgithub.com/pouriam23/Next.js-Middleware-Bypass-CVE-2025-29927-★ 2githubgithub.com/ferpalma21/Automated-Next.js-Security-Scanner-for-CVE-2025-29927★ 2githubgithub.com/TheresAFewConors/CVE-2025-29927-Testing★ 2githubgithub.com/RoyCampos/CVE-2025-29927★ 2githubgithub.com/lem0n817/CVE-2025-29927★ 2githubgithub.com/nicknisi/next-attack★ 2githubgithub.com/Oyst3r1ng/CVE-2025-29927★ 2githubgithub.com/arvion-agent/next-CVE-2025-29927★ 2githubgithub.com/Kamal-418/Vulnerable-Lab-NextJS-CVE-2025-29927★ 1githubgithub.com/m2hcz/PoC-for-Next.js-Middleware★ 1githubgithub.com/iteride/CVE-2025-29927★ 1githubgithub.com/sermikr0/nextjs-middleware-auth-bypass★ 1githubgithub.com/pixilated730/NextJS-Exploit-★ 1githubgithub.com/0xnxt1me/CVE-2025-29927★ 1githubgithub.com/rubbxalc/CVE-2025-29927★ 1githubgithub.com/kazuya256/next-js-auth-bypass★ 1githubgithub.com/ricsirigu/CVE-2025-29927★ 1githubgithub.com/Nekicj/CVE-2025-29927-exploit★ 1githubgithub.com/yugo-eliatrope/test-cve-2025-29927★ 1githubgithub.com/kuzushiki/CVE-2025-29927-test★ 1githubgithub.com/alastair66/CVE-2025-29927★ 1githubgithub.com/olimpiofreitas/CVE-2025-29927-scanner★ 1githubgithub.com/moften/CVE-2025-29927_Next.js_Auth_Bypass★ 1githubgithub.com/Bongni/CVE-2025-29927★ 1githubgithub.com/sangrok-jeon/CVE-2025-29927-Nextjs-Analysis★ 1githubgithub.com/nocomp/CVE-2025-29927-scanner★ 1githubgithub.com/diogolourencodev/middleforce★ 1githubgithub.com/liamromanis101/CVE-2025-29927-NextJS★ 1githubgithub.com/w2hcorp/CVE-2025-29927-PoC★ 1githubgithub.com/mhamzakhattak/CVE-2025-29927★ 1githubgithub.com/DanielHallbro/CVE-2025-29927-Nextjs-Bypass-PoC★ 1githubgithub.com/berraesen/nextjs-middleware-auth-bypass-lab★ 1githubgithub.com/SugiB3o/vulnerable-nextjs-14-CVE-2025-29927★ 0githubgithub.com/ValGrace/middleware-auth-bypass★ 0githubgithub.com/iSee857/CVE-2025-29927★ 0githubgithub.com/YEONDG/nextjs-cve-2025-29927★ 0githubgithub.com/Naveen-005/Next.Js-middleware-bypass-vulnerability-CVE-2025-29927★ 0githubgithub.com/maronnjapan/claude-create-CVE-2025-29927★ 0githubgithub.com/elshaheedy/CVE-2025-29927-Sigma-Rule★ 0githubgithub.com/furmak331/CVE-2025-29927★ 0githubgithub.com/0xPb1/Next.js-CVE-2025-29927★ 0githubgithub.com/jeymo092/cve-2025-29927★ 0githubgithub.com/Fomovet/cve-2025-29927★ 0githubgithub.com/0xcucumbersalad/cve-2025-29927★ 0githubgithub.com/TheWaterbug/alpr-dashboard-patches★ 0githubgithub.com/sdrtba/CVE-2025-29927★ 0githubgithub.com/gitgudKrish/cve-2025-29927-nextjs★ 0githubgithub.com/aleongx/CVE-2025-29927_Scanner★ 0githubgithub.com/Heimd411/CVE-2025-29927-PoC★ 0githubgithub.com/adjscent/vulnerable-nextjs-14-CVE-2025-29927★ 0githubgithub.com/Ev3rPalestine/0xMiddleware★ 0githubgithub.com/dedibagus/cve-2025-29927-poc★ 0githubgithub.com/0xb1lal/CVE-2025-29927★ 0githubgithub.com/JOOJIII/CVE-2025-29927★ 0githubgithub.com/Gokul-Krishnan-V-R/cve-2025-29927★ 0githubgithub.com/fahimalshihab/NextBypass★ 0githubgithub.com/Balajih4kr/cve-2025-29927★ 0githubgithub.com/pickovven/vulnerable-nextjs-14-CVE-2025-29927★ 0githubgithub.com/darklotuskdb/nextjs-CVE-2025-29927-hunter★ 0githubgithub.com/ethanol1310/POC-CVE-2025-29927-★ 0githubgithub.com/sahbaazansari/CVE-2025-29927★ 0githubgithub.com/Knotsecurity/CVE-2025-29927-NextJs-Middleware-Simulation★ 0githubgithub.com/Grand-Moomin/Vuln-Next.js-CVE-2025-29927★ 0githubgithub.com/dante01yoon/CVE-2025-29927★ 0githubgithub.com/0xPThree/next.js_cve-2025-29927★ 0githubgithub.com/bk-security/auth-header-trust-rules★ 0githubgithub.com/EarthAngel666/x-middleware-exploit★ 0githubgithub.com/sagsooz/CVE-2025-29927★ 0githubgithub.com/amitlttwo/Next.JS-CVE-2025-29927★ 0githubgithub.com/mickhacking/Thank-u-Next★ 0githubgithub.com/R3verseIN/Nextjs-middleware-vulnerable-appdemo-CVE-2025-29927★ 0githubgithub.com/zs1n/CVE-2025-29927★ 0githubgithub.com/amalpvatayam67/day10-nextjs-middleware-lab★ 0githubgithub.com/rgvillanueva28/vulnbox-easy-CVE-2025-29927★ 0githubgithub.com/NS-Projects-Unina/CTF_CVE_DSP_1★ 0githubgithub.com/lucaschanzx/CVE-2025-29927-PoC★ 0githubgithub.com/metasploit403/cve-2025-29927-lab★ 0githubgithub.com/Nayekah/Next.js-Proof-of-Concept★ 0githubgithub.com/SwapnilDeshpande/cve-2025-29927-lab★ 0githubgithub.com/kuyrathdaro/cve-2025-29927★ 0githubgithub.com/enochgitgamefied/NextJS-CVE-2025-29927★ 0githubgithub.com/yuzu-juice/CVE-2025-29927_demo★ 0githubgithub.com/all3njk/NextJS_CVE-2025-29927★ 0githubgithub.com/l1uk/nextjs-middleware-exploit★ 0githubgithub.com/hujiaozhuzhu/CVE-2025-29927__Next.js★ 0githubgithub.com/Hirainsingadia/CVE-2025-29927★ 0githubgithub.com/aleongx/CVE-2025-29927★ 0githubgithub.com/w3shinew/CVE-2025-29927★ 0githubgithub.com/Ritinify/CVE-2025-29927-PoC★ 0githubgithub.com/ayato-shitomi/WebLab_CVE-2025-29927★ 0githubgithub.com/enochgitgamefied/NextJS-CVE-2025-29927-Docker-Lab★ 0githubgithub.com/MKIRAHMET/CVE-2025-29927-PoC★ 0githubgithub.com/shahin-shadow/nextjs-auth-bypass★ 0githubgithub.com/sn1p3rt3s7/NextJS_CVE-2025-29927★ 0githubgithub.com/serhalp/test-cve-2025-29927★ 0githubgithub.com/Toddkk02/CVE-2025-29927★ 0githubgithub.com/Si-Ni/CVE-2025-29927-Proof-of-Concept★ 0githubgithub.com/s11s11/CVE-2025-29927★ 0githubgithub.com/b4sh0xf/PoC-CVE-2025-29927★ 0githubgithub.com/ticofookfook/poc-nextjs-CVE-2025-29927★ 0vulncheckvulncheck.com/xdb/606f485ea796unverifiedvulncheckvulncheck.com/xdb/9ccf7c3e3476unverifiedvulncheckvulncheck.com/xdb/7e64c0d5c958unverifiedvulncheckvulncheck.com/xdb/9931bf17ce9aunverifiedvulncheckvulncheck.com/xdb/9aadecca48ffunverifiedvulncheckvulncheck.com/xdb/3c33a028a389unverifiedvulncheckvulncheck.com/xdb/ccac829868e2unverifiedvulncheckvulncheck.com/xdb/9d84264cafc0unverifiedvulncheckvulncheck.com/xdb/ce17fda5ea0eunverifiedvulncheckvulncheck.com/xdb/b7ffa9af4976unverifiedvulncheckvulncheck.com/xdb/732e92c77220unverifiedvulncheckvulncheck.com/xdb/4f01ab59fadfunverifiedvulncheckvulncheck.com/xdb/642931d86f5funverifiedvulncheckvulncheck.com/xdb/e9ede2cc0a98unverifiedvulncheckvulncheck.com/xdb/196261a4b887unverifiedvulncheckvulncheck.com/xdb/856f20417ec0unverifiedvulncheckvulncheck.com/xdb/88a2d7e481d9unverifiedvulncheckvulncheck.com/xdb/769acb348f7eunverifiedvulncheckvulncheck.com/xdb/96b8eb3071fbunverifiedvulncheckvulncheck.com/xdb/a20d9d4a3ef9unverifiedvulncheckvulncheck.com/xdb/d93f8e59e988unverifiedvulncheckvulncheck.com/xdb/668ba5374c71unverifiedvulncheckvulncheck.com/xdb/11e310f64af2unverifiedvulncheckvulncheck.com/xdb/cedd4e3465cfunverifiedvulncheckvulncheck.com/xdb/f732acfcd062unverifiedvulncheckvulncheck.com/xdb/31fd912112fdunverifiedvulncheckvulncheck.com/xdb/ab366bce935dunverifiedvulncheckvulncheck.com/xdb/c468779ec72eunverifiedvulncheckvulncheck.com/xdb/1f968bf8ddb5unverifiedvulncheckvulncheck.com/xdb/e37333645d67unverifiedvulncheckvulncheck.com/xdb/d6c298b7c335unverifiedvulncheckvulncheck.com/xdb/913e8f5ea6c6unverifiedvulncheckvulncheck.com/xdb/048bbb1c3879unverifiedvulncheckvulncheck.com/xdb/fb68243cf5d9unverifiedvulncheckvulncheck.com/xdb/7bfe846f0256unverifiedvulncheckvulncheck.com/xdb/55eed4b0a007unverifiedvulncheckvulncheck.com/xdb/84b3af5e5b8cunverifiedvulncheckvulncheck.com/xdb/57cace7e403eunverifiedvulncheckvulncheck.com/xdb/3a29262152caunverifiedvulncheckvulncheck.com/xdb/4b0c834e9af7unverifiedvulncheckvulncheck.com/xdb/4f3380b18331unverifiedvulncheckvulncheck.com/xdb/00d1f162e925unverifiedvulncheckvulncheck.com/xdb/2f1add429d71unverifiedvulncheckvulncheck.com/xdb/5b54fe2278e7unverifiedvulncheckvulncheck.com/xdb/0a05dba55328unverifiedvulncheckvulncheck.com/xdb/62f5549bcc02unverifiedvulncheckvulncheck.com/xdb/879c5a216a90unverifiedvulncheckvulncheck.com/xdb/34222b91858funverifiedvulncheckvulncheck.com/xdb/146954f9a57bunverifiedvulncheckvulncheck.com/xdb/b8d9fccc13ccunverifiedvulncheckvulncheck.com/xdb/e1b5b7034d46unverifiedvulncheckvulncheck.com/xdb/3ae98ccea97dunverifiedvulncheckvulncheck.com/xdb/2a7e1b337763unverifiedvulncheckvulncheck.com/xdb/a4a24567290funverifiedvulncheckvulncheck.com/xdb/441991ddd347unverifiedvulncheckvulncheck.com/xdb/4e891336892eunverifiedvulncheckvulncheck.com/xdb/56769ea6f72dunverifiedvulncheckvulncheck.com/xdb/357690cfa2e3unverifiedvulncheckvulncheck.com/xdb/39a990390c28unverifiedvulncheckvulncheck.com/xdb/70ed1f6be6fbunverifiedvulncheckvulncheck.com/xdb/ebf20b63ad14unverifiedvulncheckvulncheck.com/xdb/751d55c8e070unverifiedvulncheckvulncheck.com/xdb/c6f0f626a500unverifiedvulncheckvulncheck.com/xdb/fb806a59fae5unverifiedvulncheckvulncheck.com/xdb/bf3470ff5f46unverifiedvulncheckvulncheck.com/xdb/149c2c7884b8unverifiedvulncheckvulncheck.com/xdb/70ec8fa6e178unverifiedvulncheckvulncheck.com/xdb/c3ce0f4afc74unverifiedvulncheckvulncheck.com/xdb/834958d12e1funverifiedvulncheckvulncheck.com/xdb/599cc28d6377unverifiedvulncheckvulncheck.com/xdb/b0aa5a26c434unverifiedvulncheckvulncheck.com/xdb/c304b1a61e0cunverifiedvulncheckvulncheck.com/xdb/bbc953c25fe5unverifiedvulncheckvulncheck.com/xdb/931872df3f05unverifiedvulncheckvulncheck.com/xdb/b9a379395734unverifiedvulncheckvulncheck.com/xdb/ab0e059bad2cunverifiedvulncheckvulncheck.com/xdb/15449124c3f3unverifiedvulncheckvulncheck.com/xdb/161e4016ef9eunverifiedvulncheckvulncheck.com/xdb/8338d5de007funverifiedvulncheckvulncheck.com/xdb/bad0b9008b82unverifiedvulncheckvulncheck.com/xdb/4457ba8b735dunverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.