menu
techminis

A naukri.com initiative

google-web-stories
Home

>

Hacking News

>

Next.js Mi...
source image

Dev

6d

read

346

img
dot

Image Credit: Dev

Next.js Middleware Broken Access Controls

  • An Authorization Bypass vulnerability was found in the Next.js framework, classified as CVE-2025-29927 with a critical CVSS score of 9.1.
  • The vulnerability affects self-hosted apps using Middleware for security validations, allowing unauthorized access to restricted endpoints.
  • The flaw is related to the X-Middleware-Subrequest header, which can be manipulated to bypass security controls.
  • To mitigate the vulnerability, updating Next.js to the latest version and removing the header from requests are recommended.

Read Full Article

like

20 Likes

For uninterrupted reading, download the app