Critical Next.js Middleware Auth Bypass Vulnerability (CVE-2025-29927)
A critical vulnerability in Next.js allows attackers to bypass middleware-based authorization checks in self-hosted applications using next start with output: standalone. Tracked as CVE-2025-29927, the flaw has a CVSS v3.1 score of 9.1 and impacts Next.js versions from 11.1.4 up to 13.5.6, 14.x before 14.2.25, and 15.x before 15.2.3. Affected Configurations Vulnerability Details The vulnerability …
Critical Next.js Middleware Auth Bypass Vulnerability (CVE-2025-29927) Read More »