Critical Vulnerability in Next.js Middleware (CVE-2025-29927)

Published On: Mar 27, 2025 08:56

Advisory No: TZCERT-SA-25-0078

Source: GitHub

Software Affected: Next.js 11.x, Next.js 12.x, Next.js 13.x, Next.js 14.x, Next.js 15.x

Overview

A critical vulnerability is affecting Next.js products. Exploitation of this vulnerability may allow an attacker to bypass security controls.

Description

Multiple Next.js versions are affected by a vulnerability tracked as CVE-2025-29927 with a CVSS score of 9.1. The vulnerability results from the improper validation of the internal header, which has a predictable value. Successful exploitation of the vulnerability allows attackers to bypass authentication checks within a Next.js application.

Impact

Successful exploitation of this vulnerability may allow the attackers to bypass security controls on the affected system.

Solution

Next.js has released security patches for this vulnerability. Users and administrators are encouraged to apply necessary updates.

Subscribe To TZ - CERT Newsletter

A digest of Tanzania Computer Emergency Response Team coverage of cyber-security news across the globe.

Subscribe
Report Incident