Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Critical Next.js Flaw Lets Attackers Bypass Authorization Controls

A critical vulnerability in the Next.js framework, identified as CVE-2025-29927, has been disclosed. This vulnerability allows unauthorized attackers to bypass middleware-based authorization checks by exploiting improper handling of the…

A critical vulnerability in the Next.js framework, identified as CVE-2025-29927, has been disclosed. This vulnerability allows unauthorized attackers to bypass middleware-based authorization checks by exploiting improper handling of the x-middleware-subrequest HTTP header.

This issue affects all versions of Next.js that use this header to differentiate between internal subrequests and external traffic, potentially exposing protected routes and administrative interfaces.

Role of x-middleware-subrequest Header

The x-middleware-subrequest header is used in Next.js to prevent infinite loops when middleware triggers subrequests to the server. The middleware logic reads and parses this header to detect recursive calls. However, Next.js does not sufficiently distinguish between legitimate internal subrequests and malicious external requests. As a result, an attacker can set this header arbitrarily to force middleware to skip authorization checks.

Technical Mechanism of the Vulnerability

The vulnerability lies in the following code snippet within Next.js middleware execution:

const subreq = params.request.headers["x-middleware-subrequest"]; const subrequests = typeof subreq === "string" ? subreq.split(":") : []; if (subrequests.includes(middlewareInfo.name)) { result = { response: NextResponse.next(), waitUntil: Promise.resolve(), }; continue; }

This logic splits the header value by colons into an array of strings. If any element matches middlewareInfo.name , Next.js treats the request as an internal subrequest and immediately calls NextResponse.next() , effectively skipping all downstream checks, including authentication and authorization.

Exploit Methods Across Next.js Versions

Version 12.2 and Earlier: Middleware files are named _middleware.ts under the pages directory. Here, middlewareInfo.name equals pages/_middleware . An attacker can send:

x-middleware-subrequest: pages/_middleware

Version 12.2 and Later: Middleware files are renamed middleware.ts at the root of an application or specific directory. The comparison value is simply middleware . By setting:

A critical vulnerability in the Next.js framework, identified as CVE-2025-29927, has been disclosed.
Christine Neal · Thehackingpost

Version 13.2.0 and Later: Next.js introduced MAX_RECURSION_DEPTH to limit header length and prevent infinite loops, but the header-based bypass remains viable:

x-middleware-subrequest: middleware:middleware:middleware:middleware:middleware

An attacker can craft a simple GET request:

GET /admin HTTP/1.1 Host: vulnerable-app.local x-middleware-subrequest: 1

This forces middleware to skip and return the protected /admin page, granting unauthorized access to sensitive endpoints.

Projects often layer JWT or cookie-based checks on top of middleware:

if (!req.cookies.auth_token && req.headers['x-middleware-subrequest'] !== '1') { return NextResponse.redirect('/login'); }

By sending x-middleware-subrequest: 1 , attackers bypass both middleware and token checks, gaining entry without valid credentials.

Advertisement

Scenario Header Value Result

Simple bypass 1 Middleware skipped

JWT bypass 1 + missing JWT Access granted

Role check bypass 1 + empty cookie Access granted

import fetch from 'node-fetch'; const routes = ['/admin', '/dashboard', '/settings']; async function testBypass() { for (const route of routes) { const res = await fetch(`http://localhost:3000${route}`, { headers: { 'x-middleware-subrequest': '1' } }); console.log(`${route}: ${res.status}`); } } testBypass();

This script iterates through protected routes, sending the malicious header to quickly identify vulnerable endpoints.

Patch recommendations include validating the x-middleware-subrequest header origin and enforcing server-side checks regardless of header presence. Continuous monitoring and immediate framework updates are essential to mitigate exploitation of CVE-2025-29927.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories