Next.js Patches Critical Middleware Vulnerability (CVE-2025-...
Blog post from Socket
Next.js has addressed a critical security vulnerability (CVE-2025-29927) that allowed attackers to bypass middleware-based authorization checks in self-hosted applications by spoofing the `x-middleware-subrequest` header, thus skipping authentication and authorization logic. Discovered by researchers Allam Rachid and Allam Yasser, the flaw affected all major versions up to the patched releases in versions 15.2.3, 14.2.25, 13.5.9, and 12.3.5, impacting applications using `next start` with `output: 'standalone'`. This vulnerability posed significant risks by potentially granting unauthorized access to protected resources and enabling attacks such as cache poisoning and denial-of-service. Although applications hosted on Vercel, Netlify, or deployed as static exports were unaffected, self-hosted users are urged to update to the latest patches or, as a temporary measure, block external requests containing the vulnerable header. The vulnerability has been rated 9.1 (Critical) by GitHub, highlighting its serious implications for enterprises relying on middleware for security.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.