CVE-2025-29927
by f4b52 - Monday March 24, 2025 at 04:54 PM
#1
Next.js uses an internal header x-middleware-subrequest to prevent recursive requests from triggering infinite loops. The security vulnerability shows it's possible to skip running Middleware, which could allow requests to bypass critical checks—such as authorization cookie validation—before reaching routes.

Hidden Content
You must register or login to view this content.
Reply
#2
i think john hammond did a video on this cve  ?
Ban reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect. (Permanent)
Reply
#3
(03-24-2025, 04:54 PM)f4b52 Wrote: Next.js uses an internal header x-middleware-subrequest to prevent recursive requests from triggering infinite loops. The security vulnerability shows it's possible to skip running Middleware, which could allow requests to bypass critical checks—such as authorization cookie validation—before reaching routes.
yes we look this comment
Reply
#4
lool, thx for share this cve
Reply
#5
Can't wait to check the impact of this one on some next.js applications
thanks for sharing
Reply
#6
thx share. best sharing
Reply
#7
thank you so much forr this
Reply
#8
Thank you for sharing this CVE with us
Reply
#9
Thank you for sharing this CVE with us
Reply
#10
thanks for sharing
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  CVE-2025-40554 - SolarWinds Web Help Desk Auth Bypass & RCE PoC miyako 3 73 02-07-2026, 03:32 PM
Last Post: cysc
  POC CVE-2025-24071 caca28sapo1 15 805 02-07-2026, 08:53 AM
Last Post: hacker0123
  HPE OneView RCE Exploit [CVE-2025-37164] Hawx01 8 261 02-06-2026, 07:08 PM
Last Post: hacker0123
  CitrixBleed / CVE-2023-4966 cccp 10 6,797 02-06-2026, 01:36 AM
Last Post: temptest
  WordPress LFI to RCE - CVE-2025-0366 Serious 1 457 02-05-2026, 09:53 AM
Last Post: Sammm89



 Users browsing this thread: 1 Guest(s)