CVE-2025-29927Disclosure(vercel / next.js)

CRITICALCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch vercel next.js systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware. If patching to a safe version is infeasible, it is recommend that you prevent external user requests which contain the x-middleware-subrequest header from reaching your Next.js application. This vulnerability is fixed in 12.3.5, 13.5.9, 14.2.25, and 15.2.3.

8.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285CWE-863

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • next.js

Threat summary

  • Active exploitation appears in 6 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 36 mentions across 32 observed days

What's happening

  • Active exploitation reported across 6 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 23 signals
  • Disclosure: 12 classified signals
  • General: 9 classified signals
  • Peaked 17d ago at 2 mentions (2026-04-15); latest day: 2
  • 36 total mentions across 32 days

Affected systems

Vendors
Products
next.js

Deep dive

Activity timeline36 mentions / 32d
01122Mentions · 2026-01-28: 1Mentions · 2026-02-03: 1Mentions · 2026-02-19: 1Mentions · 2026-02-22: 1Mentions · 2026-02-23: 1Mentions · 2026-02-26: 1Mentions · 2026-02-28: 1Mentions · 2026-03-09: 1Mentions · 2026-03-10: 1Mentions · 2026-03-16: 1Mentions · 2026-03-17: 1Mentions · 2026-03-25: 1Mentions · 2026-03-26: 1Mentions · 2026-04-02: 1Mentions · 2026-04-15: 2Mentions · 2026-04-30: 1Mentions · 2026-05-07: 1Mentions · 2026-05-08: 1Mentions · 2026-05-09: 1Mentions · 2026-05-14: 1Mentions · 2026-05-18: 2Mentions · 2026-06-12: 2Mentions · 2026-07-10: 1Mentions · 2026-08-25: 1Mentions · 2026-09-02: 1Mentions · 2026-09-14: 1Mentions · 2026-09-16: 1Mentions · 2026-09-17: 1Mentions · 2026-09-26: 1Mentions · 2026-09-30: 1Mentions · 2026-10-07: 1Mentions · 2026-10-08: 2PoC Mentioned / Linked · 2026-01-28: 1PoC Mentioned / Linked · 2026-04-02: 1PoC Mentioned / Linked · 2026-04-15: 1PoC Mentioned / Linked · 2026-05-08: 1PoC Mentioned / Linked · 2026-05-18: 1Exploit Tool / Code · 2026-03-10: 1Exploit Tool / Code · 2026-04-15: 1Exploit Tool / Code · 2026-05-08: 1Exploit Tool / Code · 2026-05-18: 1Active Exploitation · 2026-03-17: 1Active Exploitation · 2026-04-15: 1Active Exploitation · 2026-05-07: 1Active Exploitation · 2026-05-08: 1Active Exploitation · 2026-08-25: 1Active Exploitation · 2026-09-02: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-04-15: 1Technical Details · 2026-01-28: 1Technical Details · 2026-02-03: 1Technical Details · 2026-02-19: 1Technical Details · 2026-02-22: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-26: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-15: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-09: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-18: 2Technical Details · 2026-06-12: 2Technical Details · 2026-07-10: 1Technical Details · 2026-09-02: 1Technical Details · 2026-09-14: 1Technical Details · 2026-09-16: 1Technical Details · 2026-09-17: 1Technical Details · 2026-09-26: 101-2802-2202-2803-1603-2604-3005-0906-1209-0209-1710-0710-08
Signal classification6 categories
Disclosure
1237.5%
General
928.1%
Active Exploitation
515.6%
PoC
39.4%
Exploit
26.3%
False Positive
13.1%
Referenced assets18 URLs
Classification over time
DateTotalLabels
2026-01-281
Disclosure1
2026-02-031
General1
2026-02-191
General1
2026-02-221
General1
2026-02-231
Disclosure1
2026-02-261
General1
2026-02-281
General1
2026-03-091
General1
2026-03-101
Exploit1
2026-03-161
Disclosure1
2026-03-171
Active Exploitation1
2026-03-251
General1
2026-03-261
Disclosure1
2026-04-021
PoC1
2026-04-152
Active Exploitation1PoC1
2026-04-301
General1
2026-05-071
Active Exploitation1
2026-05-081
Exploit1
2026-05-091
General1
2026-05-141
False Positive1
2026-05-182
Disclosure1PoC1
2026-06-122
Disclosure2
2026-07-101
Disclosure1
2026-08-251
Active Exploitation1
2026-09-021
Active Exploitation1
2026-09-141
Disclosure1
2026-09-161
Disclosure1
2026-09-171
Disclosure1
2026-09-261
Disclosure1
Full discourse20 posts
  • Fawad H Syed@fawadhsdev
    False Positive

    You are exaggerating this for engagement. You are massively overstating this based on partial facts. CVE-2025-29927 was mainly a middleware auth bypass affecting some self-hosted Next.js apps, not a universal one-request compromise of every deployment. Most of the scary claims only apply to poorly segmented systems relying entirely on middleware for security. The real takeaway is that modern frameworks like Next.js have become complex enough that frontend abstractions now create real infrastructure-level security risks.

    Post summary

    The passage argues that CVE‑2025‑29927 is an overstated, limited middleware authentication bypass focused on certain self‑hosted Next.js deployments, countering claims of widespread or universal impact.

    1003357.0K
    1.2K followersView on X
  • ProjectDiscovery@pdiscoveryio
    General

    What started as bash scripts and scheduled scans evolved into full scale cloud-native execution with Nuclei Cloud. When the Next.js CVE-2025-29927 dropped, Elastic scanned 14,500 assets in under 5 minutes, something that previously took days. Read the full customer story here 👇   https://projectdiscovery.io/blog/how-elastic-scaled-proactive-detection-with-projectdiscovery-cloud

    Post summary

    The tweet reports a rapid Elastic scan of the newly released Next.js CVE‑2025‑29927 but offers no specifics on exploitation or remediation.

    0201042.5K
    41.9K followersView on X
  • GreyNoise@GreyNoiseIO
    Active Exploitation

    This week exploitation attempts arrived in same-day cohorts across unrelated flaws. Adversaries escalated a Next.js authorization bypass, CVE-2025-29927, across the final three days of the period, from no more than three daily sources to 495 across a partial final day, still climbing when the window closed. It is rated CVSS 9.1 and absent from CISA's Known Exploited Vulnerabilities catalog, so a KEV-driven queue never raises it. On 30 August adversaries checked for nine legacy Citrix flaws in a single day, running matched source sets against eight of them and producing fewer than 1,000 attempts in total. A cohort that ends within the day never sustains enough volume to cross a rate threshold. Count distinct sources per product family per day. Customers get the full weekly brief. Our public At The Edge one-pager is attached + 🔗 https://www.greynoise.io/resources/at-the-edge-clear-083126

    Post summary

    The report documents real‑world exploitation attempts against several CVEs, provides basic technical details, but does not mention PoCs, exploit code, patches, or false positive claims.

    020431.3K
    29.6K followersView on X
  • Natalia@n_bukhtiyarova
    Disclosure

    A hidden button isn't authorization, and neither is the framework's middleware (proxy in Next.js 16). One forged internal header bypassed Next.js middleware auth in March 2025 (CVE-2025-29927, CVSS 9.1). Next.js fixed four more middleware bypasses in May 2026 and a fifth in July. The check that holds sits next to the data access: every server action and every query that touches protected data asks whether this user may do this to this object. In the simplest case it is short: load the user, compare the owner, then run the query. If an agent wrote your app, grep the server actions. For each one on protected data, find where that check runs. Count the ones where it runs nowhere.

    Post summary

    The text discloses technical details of CVE-2025-29927, a Next.js middleware authorization bypass with a CVSS of 9.1, and notes subsequent fixes by the vendor.

    20010119
    53 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    New PCPJack worm targets cloud infrastructure, stealing credentials from Docker/Kubernetes/Redis while actively removing TeamPCP infections. Exploits 5 recent CVEs including CVE-2025-29927 and CVE-2026-1357 for initial access. #DFIR_Radar https://t.co/4pMlgIN6MQ

    Post summary

    The tweet announces a new worm that is actively exploiting at least two recent CVEs to gain initial access and steal credentials from cloud environments.

    100111.1K
    1.7K followersView on X
  • Anirudha Kulkarni@4n1rudh4
    Active Exploitation

    We just got hit with worst cybersecurity attack. Issue traced back to Opus committing "Good for now, not a big deal" on a well known vulnerability from last year "CVE-2025-29927" In order to fix an issue, Opus 4.6 chose to downgrade Nextjs to 15.0.3 which has sever known issue.

    Post summary

    The post details that a real-world attack exploited CVE-2025-29927, and Opus mitigated the issue by downgrading Next.js to version 15.0.3.

    10020269
    198 followersView on X
  • Mia Davis@codewithmia
    General

    (CVE-2025-29927). This is what PreBreach scans for.

    Post summary

    The text merely references CVE‑2025‑29927 and notes that PreBreach scans for it, without providing additional details.

    00030162
    40 followersView on X
  • Pluralsight@pluralsight
    General

    🚨 CVE-2026-1281 Critical Code Injection in Ivanti EPMM: What You Should Know 🚨 Discover the key information you need to know about CVE-2025-29927, an authentication bypass vulnerability in the middleware layer in Vercel’s Next.js. Learn more: https://plrsg.ht/4c4BxVR https://t.co/aD5hARFXHm

    Post summary

    The tweet announces CVE-2025-29927, an authentication bypass in Vercel’s Next.js, links to further information, but provides no PoC, exploit code, patch details, or evidence of active exploitation.

    000031.5K
    228.5K followersView on X
  • Naci@logapsec
    Exploit

    1/4: Next.js sitenizin kapısını açık mı bıraktınız? (CVE-2025-29927) 🚨 Tüm auth ve CSP katmanınızı tek bir header ile geçmek mümkün. Şu anki meta: **x-middleware-subrequest** suistimali. Nasıl çalıştığını ve korunma yollarını inceleyelim. 🧵 2/4:Hata Nerede? 🔍 Middleware, Next.js'in "gatekeeper"ıdır. Ancak bazı versiyonlarda dışarıdan gelen x-middleware-subrequest header'ı Next.js'i şu konuda kandırabiliyor: "Bu istek zaten middleware'den geçti, tekrar kontrol etme." 3/4:Exploit Vektörü ☣️ İstek başlığına şunu eklemek yeterli: • Header: x-middleware-subrequest • Value: http://middlewareInfo.name (örn: src/middleware) Sonuç: Auth guard'lar devre dışı, veriler açıkta. 🔓 4/4: Acil Eylem Planı ✅ • **Versiyon Güncelle:** 15.2.3+ veya 14.2.25+ sürümüne hemen geçin. • **WAF/Edge:** Dışarıdan gelen x-middleware-subrequest başlıklarını WAF üzerinden bloklayın. #NextJS #CyberSecurity #WebDev #LemmaAI

    Post summary

    The thread discloses CVE‑2025‑29927 in Next.js, detailing a header-based bypass of authentication and recommending updates or WAF blocking as mitigation.

    00011282
    11 followersView on X
  • Ayush Rijith@AyushRijith
    General

    @_ar9av @prismor_dev the critical ones include CVE-2025-29927 , CVE-2025-7783 , CVE-2023-50447 , CVE-2025-43859, CVE-2023-39662 , CVE-2024-23751 , CVE-2025-1793 this one has a sql injection vulnerability , CVE-2023-39631 , CVE-2024-3829 , CVE-2023-6730 , CVE-2025-64712 and more..

    Post summary

    The tweet lists several CVEs, noting only that CVE‑2025‑1793 involves a SQL injection, but it provides no deeper technical detail, PoC, patch, or exploitation information.

    0002079
    6 followersView on X
  • ♫NØX♥H♪@_Why_Noot

    NØX Echo Lineage Signal: CVE-2025-29927 Entity: next.js Lineage: Public vulnerability → Public exploit/PoC → Observed exploitation Relationship: - next.js → CVE-2025-29927 → Evidence → Operational Risk Current State: DISCLOSED, POC_AVAILABLE, ACTIVE_EXPLOITATION

    1000024
    8 followersView on X
  • 🦇 ©@Blackstone0123

    @zhero___ Regarding the Next.js middleware bypass (CVE-2025-29927) did you report it to Vercel first and only go after bug bounty programs after the fix, or did you also report it to vulnerable programs immediately after report it to vendor ? Curious about your approach.

    0001053
    92 followersView on X
  • CyberPulse@CyberPulse56

    ‼️🇺🇸 CRITICAL VULNERABILITY CLAIM — NYU SUBDOMAIN Threat actor ShadowByt3S claims to have identified a potentially vulnerable New York University (NYU) subdomain affected by CVE-2025-29927, a critical vulnerability with a reported CVSS score of 9.1. 🔎 Claimed status: Vulnerability scan confirmed 🎯 Target: NYU subdomain 🆔 CVE: CVE-2025-29927 💰 Asking price: $60 💳 Payment: BTC / XMR ⚠️ The actor states the vulnerability has not yet been exploited and is offering the claimed finding for sale. The claim, affected subdomain, scan results and exploitability have not been independently verified. #CyberSecurity #CVE #Vulnerability #NYU #ThreatIntel #CyberThreat #InfoSec

    00010443
    3.8K followersView on X
  • Auditd.Pro@auditdpro
    Disclosure

    CVE-2025-29927. CVSS 9.1.

    Post summary

    The tweet discloses CVE-2025-29927 and notes its CVSS score of 9.1, indicating a high‑severity vulnerability.

    1000027
    19 followersView on X
  • Auditd.Pro@auditdpro
    Disclosure

    For a while in 2025 you could walk past authentication on a huge number of Next.js apps by adding one header to a request. CVE-2025-29927. Severity 9.1. #nextjs

    Post summary

    The tweet discloses CVE-2025-29927 as a Next.js authentication bypass vulnerability exploitable via a single header with a severity of 9.1, but provides no PoC, exploit tool, patch, or active exploitation claim.

    1000029
    18 followersView on X
  • Claw & Order | Prompt Crimes Unit@ClawAndOrderAI
    Active Exploitation

    CASE FILE: Developer used Claude Code and OpenAI Codex to "vibe code" a Next.js app. AI pinned a vulnerable dependency version. Result? CVE-2025-29927 exploited, middleware bypassed, cryptominer deployed. The attack chain: AI-generated project → vulnerable dependency → automated scan → cryptominer. Speed without brakes = security debt at scale. 📁⛏️⚖️

    Post summary

    A developer used AI to generate a Next.js project, which incorporated a vulnerable dependency pinned by the AI. The resulting exploitation of CVE‑2025‑29927 bypassed middleware and deployed a cryptominer, demonstrating active use of the flaw.

    0001046
    27 followersView on X
  • DataHogo@DataHogo
    Disclosure

    Your Next.js middleware runs on every request. Or it's supposed to. CVE-2025-29927 let attackers skip it entirely — with a single HTTP header. No exploit code. No auth bypass tool. Just curl and one header. If middleware was your only auth layer, every protected route was open. Affected: Next.js 11.1.4 → 15.2.2. Four years of releases. Full breakdown, what to check in your logs, and how to add a second auth layer 👇 https://datahogo.com/en/blog/cve-2025-29927-nextjs-middleware-auth-bypass #nextjs #webdev #appsec

    Post summary

    The blog announces CVE‑2025‑29927, a middleware auth bypass in Next.js triggered by a single HTTP header, and advises adding a second auth layer to protect routes.

    010001.2K
    3 followersView on X
  • DataHogo@DataHogo
    PoC

    Someone added one HTTP header to a request. The dashboard loaded. No login. No session. No credentials. Just: x-middleware-subrequest: middleware:middleware:middleware:middleware:middleware That's CVE-2025-29927. It bypassed every Next.js middleware check in versions 11.1.4 through 15.2.2. Admin panel? Open. Billing page? Open. User data? Open. If your auth lives only in middleware.ts — check your version. #nextjs #webdev #cybersecurity

    Post summary

    The tweet details a CVE‑2025‑29927 privilege‑escalation in Next.js by inserting a specific HTTP header, exposing admin and billing pages without authentication; no patch or evidence of active exploitation is mentioned.

    000101.2K
    3 followersView on X
  • ShipWithAI@shipwithaiio
    PoC

    And then there's CVE-2025-29927. A single curl command bypassed ALL middleware auth checks in Next.js. Every app that relied on middleware-only auth was vulnerable. If your "protected" routes only check auth in middleware you have a security hole, not a feature.

    Post summary

    A single curl command demonstrates a middleware auth bypass in Next.js, exposing a serious vulnerability for apps that rely on middleware-only authentication, yet no active exploitation or patch details are mentioned.

    10000223
    23 followersView on X
  • ♫Why♥Not♪@Python_s_

    NØØT Security Alerts Classification: Critical CVE: CVE-2025-29927 Product: vercel / next.js Summary: VulnCheck reports real-world exploitation activity affecting vercel / next.js. Evidence: Public PoC/exploit available; Active exploitation reported; Live exploitation observed by VulnCheck canaries Impact: The vulnerability can materially affect exposed systems; verify vendor-specific impact and affected versions. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. Date: 28 Mar 2025 Source: https://vulncheck.com/xdb/bf3470ff5f46 #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #next_js #CVE_2025_29927 #ActiveExploitation #Exploit

    0000031
    227 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvercelnext.js-node.js-

Explore more