Severe Next.js Security Threat Enables Intruders to Circumvent Middleware Authorization Verifications

An alarming security loophole has come to light in the Next.js React framework which may be leveraged to elude authorization verifications in specific scenarios.
The vulnerability, identified as CVE-2025-29927, has been assigned a CVSS score of 9.

An alarming security loophole has come to light in the Next.js React framework which may be leveraged to elude authorization verifications in specific scenarios.
The vulnerability, identified as CVE-2025-29927, has been assigned a CVSS score of 9.1 out of 10.0.
According to Next.js, “To avoid infinite loops caused by recursive requests, Next.js employs an internal header x-middleware-subrequest.”

About Author

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.