URL has been copied successfully!
Next.js Vulnerability Exposes Middleware Security Gaps
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Next.js Vulnerability Exposes Middleware Security Gaps

On March 21, 2025, a critical authorization bypass vulnerability in Next.js, identified as CVE-2025-29927, was disclosed with a CVSS score of 9.1. This framework’s middleware handling flaw enables attackers to bypass authentication and authorization, exposing sensitive routes to unauthorized access. Exploiting this vulnerability does not require authentication, providing attackers with direct access to protected routes….

First seen on securityboulevard.com

Jump to article: securityboulevard.com/2025/04/next-js-vulnerability-exposes-middleware-security-gaps/

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link