← All CVEs NewScan detects
critical

CVE-2025-29927

Next.js middleware authorization bypass - the internal x-middleware-subrequest header skips middleware entirely

Severity
critical
Affected product
Next.js
Affected versions
Next.js ≥ 15.0.0, < 15.2.3
Affected versions
Next.js ≥ 14.0.0, < 14.2.25
Affected versions
Next.js ≥ 13.0.0, < 13.5.9
Affected versions
Next.js < 12.3.5
Fixed in
Next.js 15.2.3
Fixed in
Next.js 14.2.25
Fixed in
Next.js 13.5.9
Fixed in
Next.js 12.3.5
Added to NewScan
2026-07-21
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints Next.js from its response and reports this CVE when the detected version falls inside the affected range below.

Backfilled 2026-08-02 (docs/todo.md item 1).

COMPONENT VERSION RANGE

NewScan fingerprints Next.js from its response and reports this CVE when the detected version falls inside the affected range below.

Backfilled 2026-08-02 (docs/todo.md item 1).

COMPONENT VERSION RANGE

NewScan fingerprints Next.js from its response and reports this CVE when the detected version falls inside the affected range below.

Backfilled 2026-08-02 (docs/todo.md item 1).

COMPONENT VERSION RANGE

NewScan fingerprints Next.js from its response and reports this CVE when the detected version falls inside the affected range below.

Backfilled 2026-08-02 (docs/todo.md item 1).

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →