Next.js contains a critical middleware bypass vulnerability affecting versions 11.1.4 through 15.2.2.
The vulnerability allows attackers to bypass middleware security controls by sending a specially crafted
'x-middleware-subrequest' header, which can lead to authorization bypass and other security control circumvention.
id: CVE-2025-29927
info:
name: Next.js Middleware Bypass
author: pdresearch,pdteam,hazedic
se
...