A critical vulnerability in Next.js middleware allows attackers to bypass authorization checks by manipulating the x-middleware-subrequest header. This flaw affects Next.js versions prior to 14.2.25 and 15.2.3, potentially granting unauthorized access to sensitive resources.
id: CVE-2025-29927-HEADLESS
info:
name: Next.js Middleware Authorization Bypass
author: ademkin
...