CVE-2025-29927
Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware. If patching to a safe version is infeasible, it is recommend that you prevent external user requests which contain the x-middleware-subrequest header from reaching your Next.js application. This vulnerability is fixed in 12.3.5, 13.5.9, 14.2.25, and 15.2.3.
System detected CVE-2025-29927 with a risk of 3.95
System detected CVE-2025-29927 with a risk of 3.95
System
System detected CVE-2025-29927 with a risk of 3.95
System
System
System
- S
Sebastian Kawelke marked CVE-2025-29927 as false positive - component not present
Not installed anymore...
System updated the risk assessment from 3.95 to 7.64
System recalculated raw risk assessment
System updated the risk assessment from 3.95 to 7.64
System recalculated raw risk assessment
System updated the risk assessment from 3.95 to 7.64
System recalculated raw risk assessment
System fixed CVE-2025-29927
System fixed CVE-2025-29927
System fixed CVE-2025-29927
System detected CVE-2025-29927 with a risk of 7.65
System updated the risk assessment from 7.65 to 7.64
System recalculated raw risk assessment
Add a comment
Affected component
next