🗓️ UPCOMING WEBINAR | OCTOBER 6TH: How CISOs Should Think About Offensive Security in the Age of AI Register Now 🗓️ UPCOMING WEBINAR | OCTOBER 6TH
CyCognito Blog

Posts tagged ‘Unauthorized Access’

Search the Blog

By Emma Zaballos

CVE-2025-29927 is a critical authorization vulnerability (CVSS 9.1) in self-hosted Next.js applications using middleware, allowing attackers to bypass security checks with a crafted x-middleware-subrequest header. It affects versions 11.1.5 to 15.2.2, with patches available in newer releases. While there are no active exploits reported as of March 27, 2025, CyCognito has issued guidance to help organizations assess and mitigate exposure.

Read more about Emerging Threat: Next.js CVE-2025-29927