CVE-2025-29927

CRITICAL EXPLOITED NUCLEI LAB

Next.js Middleware Bypass

Title source: nuclei

Description

Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware. If patching to a safe version is infeasible, it is recommend that you prevent external user requests which contain the x-middleware-subrequest header from reaching your Next.js application. This vulnerability is fixed in 12.3.5, 13.5.9, 14.2.25, and 15.2.3.

Exploits (132)

nomisec WORKING POC 96 stars
by aydinnyunus · poc
https://github.com/aydinnyunus/CVE-2025-29927
nomisec SCANNER 82 stars
by AnonKryptiQuz · remote
https://github.com/AnonKryptiQuz/NextSploit
nomisec SCANNER 19 stars
by websecnl · remote
https://github.com/websecnl/CVE-2025-29927-PoC-Exploit
nomisec SCANNER 18 stars
by 6mile · remote
https://github.com/6mile/nextjs-CVE-2025-29927
nomisec WORKING POC 15 stars
by azu · remote
https://github.com/azu/nextjs-cve-2025-29927-poc
nomisec WORKING POC 14 stars
by lirantal · remote
https://github.com/lirantal/vulnerable-nextjs-14-CVE-2025-29927
nomisec WRITEUP 9 stars
by MuhammadWaseem29 · remote
https://github.com/MuhammadWaseem29/CVE-2025-29927-POC
nomisec WORKING POC 9 stars
by phoscoder · poc
https://github.com/phoscoder/ghost-route
nomisec SCANNER 8 stars
by gotr00t0day · remote
https://github.com/gotr00t0day/CVE-2025-29927
nomisec WORKING POC 8 stars
by UNICORDev · remote
https://github.com/UNICORDev/exploit-CVE-2025-29927
nomisec WORKING POC 7 stars
by KaztoRay · poc
https://github.com/KaztoRay/CVE-2025-29927-Research
nomisec SCANNER 5 stars
by HoumanPashaei · remote
https://github.com/HoumanPashaei/CVE-2025-29927
nomisec WORKING POC 5 stars
by strobes-security · poc
https://github.com/strobes-security/nextjs-vulnerable-app
nomisec WORKING POC 5 stars
by kOaDT · remote
https://github.com/kOaDT/poc-cve-2025-29927
nomisec WORKING POC 5 stars
by fourcube · remote
https://github.com/fourcube/nextjs-middleware-bypass-demo
nomisec WORKING POC 4 stars
by t3tra-dev · remote
https://github.com/t3tra-dev/cve-2025-29927-demo
nomisec WRITEUP 4 stars
by Ademking · poc
https://github.com/Ademking/CVE-2025-29927
nomisec SCANNER 4 stars
by RoyCampos · remote
https://github.com/RoyCampos/CVE-2025-29927
nomisec WORKING POC 4 stars
by alihussainzada · remote
https://github.com/alihussainzada/CVE-2025-29927-PoC
nomisec WORKING POC 3 stars
by luq0x · remote
https://github.com/luq0x/0xMiddleware
nomisec WORKING POC 3 stars
by c0dejump · remote
https://github.com/c0dejump/CVE-2025-29927-check
nomisec SCANNER 3 stars
by 0xWhoknows · remote
https://github.com/0xWhoknows/CVE-2025-29927
nomisec WORKING POC 3 stars
by Eve-SatOrU · infoleak
https://github.com/Eve-SatOrU/POC-CVE-2025-29927
nomisec SCANNER 2 stars
by ferpalma21 · poc
https://github.com/ferpalma21/Automated-Next.js-Security-Scanner-for-CVE-2025-29927
nomisec WORKING POC 2 stars
by lem0n817 · poc
https://github.com/lem0n817/CVE-2025-29927
nomisec WORKING POC 2 stars
by pouriam23 · poc
https://github.com/pouriam23/Next.js-Middleware-Bypass-CVE-2025-29927-
nomisec WORKING POC 2 stars
by Oyst3r1ng · poc
https://github.com/Oyst3r1ng/CVE-2025-29927
nomisec SCANNER 2 stars
by Nekicj · poc
https://github.com/Nekicj/CVE-2025-29927-exploit
nomisec WORKING POC 2 stars
by arvion-agent · poc
https://github.com/arvion-agent/next-CVE-2025-29927
nomisec SCANNER 2 stars
by TheresAFewConors · remote
https://github.com/TheresAFewConors/CVE-2025-29927-Testing
github WORKING POC 2 stars
by ThemeHackers · pythonremote
https://github.com/ThemeHackers/CVE-2025-29972
nomisec SCANNER 2 stars
by emadshanab · infoleak
https://github.com/emadshanab/CVE-2025-29927
nomisec WORKING POC 2 stars
by yugo-eliatrope · remote
https://github.com/yugo-eliatrope/test-cve-2025-29927
nomisec WRITEUP 1 stars
by kh4sh3i · poc
https://github.com/kh4sh3i/CVE-2025-29927
nomisec WORKING POC 1 stars
by w2hcorp · remote
https://github.com/w2hcorp/CVE-2025-29927-PoC
nomisec SCANNER 1 stars
by pixilated730 · remote
https://github.com/pixilated730/NextJS-Exploit-
nomisec SCANNER 1 stars
by nocomp · poc
https://github.com/nocomp/CVE-2025-29927-scanner
nomisec SCANNER 1 stars
by olimpiofreitas · infoleak
https://github.com/olimpiofreitas/CVE-2025-29927-scanner
nomisec WORKING POC 1 stars
by rubbxalc · remote
https://github.com/rubbxalc/CVE-2025-29927
nomisec WORKING POC 1 stars
by Kamal-418 · poc
https://github.com/Kamal-418/Vulnerable-Lab-NextJS-CVE-2025-29927
nomisec WORKING POC 1 stars
by nicknisi · remote
https://github.com/nicknisi/next-attack
nomisec SCANNER 1 stars
by jmbowes · remote
https://github.com/jmbowes/NextSecureScan
nomisec WORKING POC 1 stars
by alastair66 · poc
https://github.com/alastair66/CVE-2025-29927
nomisec WORKING POC 1 stars
by EQSTLab · remote
https://github.com/EQSTLab/CVE-2025-29927
nomisec WORKING POC 1 stars
by m2hcz · remote
https://github.com/m2hcz/PoC-for-Next.js-Middleware
nomisec WORKING POC 1 stars
by kuzushiki · poc
https://github.com/kuzushiki/CVE-2025-29927-test
nomisec WORKING POC 1 stars
by sermikr0 · poc
https://github.com/sermikr0/nextjs-middleware-auth-bypass
nomisec WORKING POC 1 stars
by lstudlo · poc
https://github.com/lstudlo/nextjs-cve-demo
github WORKING POC 1 stars
by exploitintel · pythonpoc
https://github.com/exploitintel/eip-pocs-and-cves/tree/main/CVE-2025-29927
nomisec WORKING POC 1 stars
by kazuya256 · poc
https://github.com/kazuya256/next-js-auth-bypass
nomisec WORKING POC 1 stars
by ricsirigu · poc
https://github.com/ricsirigu/CVE-2025-29927
nomisec SCANNER 1 stars
by moften · poc
https://github.com/moften/CVE-2025-29927_Next.js_Auth_Bypass
nomisec WORKING POC 1 stars
by iteride · infoleak
https://github.com/iteride/CVE-2025-29927
nomisec SCANNER 1 stars
by liamromanis101 · infoleak
https://github.com/liamromanis101/CVE-2025-29927-NextJS
github WORKING POC 1 stars
by TH-SecForge · pythonremote
https://github.com/TH-SecForge/CVE-2025-29972
nomisec WORKING POC 1 stars
by Bongni · poc
https://github.com/Bongni/CVE-2025-29927
nomisec STUB 1 stars
by 0xnxt1me · poc
https://github.com/0xnxt1me/CVE-2025-29927
nomisec WORKING POC
by Knotsecurity · poc
https://github.com/Knotsecurity/CVE-2025-29927-NextJs-Middleware-Simulation
nomisec WORKING POC
by Gokul-Krishnan-V-R · poc
https://github.com/Gokul-Krishnan-V-R/cve-2025-29927
nomisec WORKING POC
by fahimalshihab · poc
https://github.com/fahimalshihab/NextBypass
nomisec WORKING POC
by 0xPb1 · poc
https://github.com/0xPb1/Next.js-CVE-2025-29927
nomisec WORKING POC
by Naveen-005 · poc
https://github.com/Naveen-005/Next.Js-middleware-bypass-vulnerability-CVE-2025-29927
nomisec STUB
by pickovven · poc
https://github.com/pickovven/vulnerable-nextjs-14-CVE-2025-29927
nomisec SCANNER
by darklotuskdb · poc
https://github.com/darklotuskdb/nextjs-CVE-2025-29927-hunter
nomisec WORKING POC
by DanielHallbro · poc
https://github.com/DanielHallbro/CVE-2025-29927-Nextjs-Bypass-PoC
nomisec WORKING POC
by 0xcucumbersalad · poc
https://github.com/0xcucumbersalad/cve-2025-29927
nomisec WORKING POC
by rgvillanueva28 · poc
https://github.com/rgvillanueva28/vulnbox-easy-CVE-2025-29927
nomisec WORKING POC
by amalpvatayam67 · poc
https://github.com/amalpvatayam67/day10-nextjs-middleware-lab
nomisec WORKING POC
by enochgitgamefied · poc
https://github.com/enochgitgamefied/NextJS-CVE-2025-29927
nomisec WRITEUP
by elshaheedy · poc
https://github.com/elshaheedy/CVE-2025-29927-Sigma-Rule
nomisec WORKING POC
by R3verseIN · poc
https://github.com/R3verseIN/Nextjs-middleware-vulnerable-appdemo-CVE-2025-29927
nomisec STUB
by serhalp · poc
https://github.com/serhalp/test-cve-2025-29927
nomisec WRITEUP
by BilalGns · poc
https://github.com/BilalGns/CVE-2025-29927
nomisec WORKING POC
by JOOJIII · poc
https://github.com/JOOJIII/CVE-2025-29927
nomisec WORKING POC
by yuzu-juice · poc
https://github.com/yuzu-juice/CVE-2025-29927_demo
gitlab WORKING POC
by ThemeHackers · poc
https://gitlab.com/ThemeHackers/CVE-2025-29972
nomisec SCANNER
by ticofookfook · remote
https://github.com/ticofookfook/poc-nextjs-CVE-2025-29927
nomisec SCANNER
by iSee857 · remote
https://github.com/iSee857/CVE-2025-29927
nomisec WORKING POC
by jeymo092 · remote
https://github.com/jeymo092/cve-2025-29927
nomisec WORKING POC
by maronnjapan · remote
https://github.com/maronnjapan/claude-create-CVE-2025-29927
nomisec SCANNER
by aleongx · remote
https://github.com/aleongx/CVE-2025-29927_Scanner
nomisec WORKING POC
by Heimd411 · remote
https://github.com/Heimd411/CVE-2025-29927-PoC
nomisec WORKING POC
by dante01yoon · remote
https://github.com/dante01yoon/CVE-2025-29927
nomisec WORKING POC
by sn1p3rt3s7 · remote
https://github.com/sn1p3rt3s7/NextJS_CVE-2025-29927
nomisec SCANNER
by Balajih4kr · remote
https://github.com/Balajih4kr/cve-2025-29927
nomisec WORKING POC
by YEONDG · remote
https://github.com/YEONDG/nextjs-cve-2025-29927
nomisec WORKING POC
by l1uk · remote
https://github.com/l1uk/nextjs-middleware-exploit
nomisec WORKING POC
by ethanol1310 · remote
https://github.com/ethanol1310/POC-CVE-2025-29927-
nomisec WORKING POC
by mhamzakhattak · remote
https://github.com/mhamzakhattak/CVE-2025-29927
nomisec SCANNER
by Hirainsingadia · remote
https://github.com/Hirainsingadia/CVE-2025-29927
nomisec STUB
by EarthAngel666 · infoleak
https://github.com/EarthAngel666/x-middleware-exploit
nomisec WORKING POC
by enochgitgamefied · remote
https://github.com/enochgitgamefied/NextJS-CVE-2025-29927-Docker-Lab
nomisec SCANNER
by sagsooz · remote
https://github.com/sagsooz/CVE-2025-29927
nomisec WORKING POC
by SugiB3o · remote
https://github.com/SugiB3o/vulnerable-nextjs-14-CVE-2025-29927
nomisec SCANNER
by amitlttwo · remote
https://github.com/amitlttwo/Next.JS-CVE-2025-29927
nomisec WORKING POC
by mickhacking · infoleak
https://github.com/mickhacking/Thank-u-Next
nomisec WORKING POC
by zs1n · infoleak
https://github.com/zs1n/CVE-2025-29927
nomisec WORKING POC
by MKIRAHMET · infoleak
https://github.com/MKIRAHMET/CVE-2025-29927-PoC
nomisec WORKING POC
by adjscent · infoleak
https://github.com/adjscent/vulnerable-nextjs-14-CVE-2025-29927
nomisec WORKING POC
by Si-Ni · remote
https://github.com/Si-Ni/CVE-2025-29927-Proof-of-Concept
nomisec WORKING POC
by ValGrace · poc
https://github.com/ValGrace/middleware-auth-bypass
nomisec WORKING POC
by Grand-Moomin · remote
https://github.com/Grand-Moomin/Vuln-Next.js-CVE-2025-29927
nomisec WRITEUP
by sdrtba · infoleak
https://github.com/sdrtba/CVE-2025-29927
nomisec WRITEUP
by b4sh0xf · infoleak
https://github.com/b4sh0xf/PoC-CVE-2025-29927
nomisec WORKING POC
by 0xPThree · poc
https://github.com/0xPThree/next.js_cve-2025-29927
nomisec WORKING POC
by sahbaazansari · poc
https://github.com/sahbaazansari/CVE-2025-29927
nomisec NO CODE
by aleongx · poc
https://github.com/aleongx/CVE-2025-29927
github WORKING POC
by enciphers-team · pythonpoc
https://github.com/enciphers-team/cve-exploits/tree/main/cve-2025-29927.py
nomisec WORKING POC
by furmak331 · poc
https://github.com/furmak331/CVE-2025-29927
nomisec WRITEUP
by dedibagus · poc
https://github.com/dedibagus/cve-2025-29927-poc
nomisec WRITEUP
by N3k0t-dev · poc
https://github.com/N3k0t-dev/bughunter-cyber-intel-dashboard
nomisec SCANNER
by w3shinew · poc
https://github.com/w3shinew/CVE-2025-29927
github WRITEUP
by lucaschanzx · typescriptpoc
https://github.com/lucaschanzx/CVE-2025-29927-PoC
nomisec SUSPICIOUS
by 0xb1lal · poc
https://github.com/0xb1lal/CVE-2025-29927
nomisec WORKING POC
by ayato-shitomi · poc
https://github.com/ayato-shitomi/WebLab_CVE-2025-29927
exploitdb WORKING POC
by kOaDT · textwebappsmultiple
https://www.exploit-db.com/exploits/52124
vulncheck_xdb SUSPICIOUS
remote
https://github.com/goncalocsousa1/CVE-2025-29927
vulncheck_xdb SCANNER
remote
https://github.com/moften/CVE-2025-29927
vulncheck_xdb WORKING POC
infoleak
https://github.com/aayush256-sys/next-js-auth-bypass
vulncheck_xdb SCANNER
infoleak
https://github.com/takumade/ghost-route
vulncheck_xdb SCANNER
infoleak
https://github.com/diogolourencodev/middleforce
vulncheck_xdb WORKING POC
infoleak
https://github.com/AventurineJun/CVE-2025-29927-Research
vulncheck_xdb SCANNER
remote
https://github.com/Slvignesh05/CVE-2025-29927

Nuclei Templates (2)

Next.js Middleware Authorization Bypass
CRITICALby ademking
Next.js Middleware Bypass
CRITICALby pdresearch,pdteam,hazedic
Shodan: x-middleware-rewrite
FOFA: x-middleware-rewrite

Scores

CVSS v3 9.1
EPSS 0.9295
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Lab Environment

Lab screenshot
vulnerable
docker pull ghcr.io/exploitintel/cve-2025-29927-vulnerable:latest
All Labs GitHub

Exploitation Intel

VulnCheck KEV 2025-03-28

Classification

CWE
CWE-285 CWE-863
Status published

Affected Products (2)

vercel/next.js < 12.3.5
npm/next < 13.5.9npm

Timeline

Published Mar 21, 2025
Tracked Since Feb 18, 2026