S4E just found a medium vulnerable javascript library scanner
critical·Product Based Web Vulnerabilities·Updated Mar 24, 2025

CVE-2025-29927 Scanner

CVE-2025-29927 Scanner - Authorization Bypass vulnerability in Next.js X Middleware Subrequest

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
27
Times Used
by S4E users
7
Assets Scanned
domains & IPs
11
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-29927
9.1
CVSScritical
Exploitable remotely over the internet · no authentication required.

Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware. If patching to a safe version is infeasible, it is recommend that you prevent external user requests which contain the x-middleware-subrequest header from reaching your Next.js application. This vulnerability is fixed in 12.3.5, 13.5.9, 14.2.25, and 15.2.3.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
next.jsby vercel
>= 11.1.4, < 12.3.5
Updated Aug 19, 2026View on NVD →
Detail

Next.js is a popular React framework used by developers to build server-side rendered and static web applications. It is widely adopted for creating dynamic websites and applications due to its performance optimization features and ease of use. Companies and developers across industries rely on Next.js for building scalable and secure web solutions. The middleware functionality in Next.js is critical for implementing security controls, routing, and other application logic.

The vulnerability identified in Next.js involves a middleware bypass that allows attackers to circumvent security controls by exploiting a specially crafted header, 'x-middleware-subrequest.' This bypass can lead to unauthorized access to protected resources and compromise the integrity of the application’s security mechanisms.

Technically, the vulnerability stems from improper handling of the 'x-middleware-subrequest' header within middleware logic, enabling attackers to bypass authorization checks. The affected versions include 11.1.4 through 15.2.2, where this flaw can be exploited by sending malicious requests containing the crafted header.

If exploited, this vulnerability could result in severe consequences such as unauthorized access to sensitive data, disruption of application functionality, or circumvention of critical security controls like authentication and authorization mechanisms.

REFERENCES

 

Solution Advice
  • Upgrade to Next.js version 14.2.25 or 15.2.3 or later.
  • Review middleware configurations to ensure proper validation of headers.
  • Conduct regular security testing to identify potential bypass vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.