Severe Next.js Security Threat Enables Intruders to Circumvent Middleware Authorization Verifications
An alarming security loophole has come to light in the Next.js React framework which may be leveraged to elude authorization verifications in specific scenarios.
The vulnerability, identified as CVE-2025-29927, has been assigned a CVSS score of 9.1 out of 10.0.
According to Next.js, “To avoid infinite loops caused by recursive requests, Next.js employs an internal header x-middleware-subrequest.”
The vulnerability, identified as CVE-2025-29927, has been assigned a CVSS score of 9.1 out of 10.0.
According to Next.js, “To avoid infinite loops caused by recursive requests, Next.js employs an internal header x-middleware-subrequest.”
