Next.js Middleware 15.2.2 - Authorization Bypass

Next.js Middleware 15.2.2 - Authorization Bypass

Published 5 Sep 2026Updated 5 Sep 2026378 sources
CVSS 9.1 ✓ VERIFIED REFERENCE

What happened

A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.

Affected versions

Unknown product: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
Exploit-DB 52124Next.js Middleware 15.2.2 - Authorization BypasskOaDT2025-04-05VerifiedPoC-in-GitHub · serhalp/test-cve-2025-29927Verify Next.js CVE-2025-29927 on Netlify not vulnerable★ 0serhalp2025-03-22CandidatePoC-in-GitHub · Ademking/CVE-2025-29927Next.js Middleware Authorization Bypass★ 4Ademking2025-03-22CandidatePoC-in-GitHub · 6mile/nextjs-CVE-2025-29927A Nuclei template to detect CVE-2025-29927 the Next.js authentication bypass vulnerability★ 196mile2025-03-23CandidatePoC-in-GitHub · azu/nextjs-cve-2025-29927-pocNext.js PoC for CVE-2025-29927★ 15azu2025-03-23CandidatePoC-in-GitHub · lirantal/vulnerable-nextjs-14-CVE-2025-29927★ 14lirantal2025-03-23CandidatePoC-in-GitHub · aydinnyunus/CVE-2025-29927CVE-2025-29927 Proof of Concept★ 103aydinnyunus2025-03-23CandidatePoC-in-GitHub · ticofookfook/poc-nextjs-CVE-2025-29927★ 0ticofookfook2025-03-23CandidatePoC-in-GitHub · t3tra-dev/cve-2025-29927-demoNext.js における認可バイパスの脆弱性 CVE-2025-29927 を再現するデモです。★ 4t3tra-dev2025-03-23CandidatePoC-in-GitHub · websecnl/CVE-2025-29927-PoC-ExploitProof-of-Concept for Authorization Bypass in Next.js Middleware★ 20websecnl2025-03-23CandidatePoC-in-GitHub · MuhammadWaseem29/CVE-2025-29927-POCAuthorization Bypass in Next.js Middleware★ 10MuhammadWaseem292025-03-23CandidatePoC-in-GitHub · strobes-security/nextjs-vulnerable-appCVE-2025-29927 lab★ 6strobes-security2025-03-24CandidatePoC-in-GitHub · RoyCampos/CVE-2025-29927CVE-2025-29927 Exploit Checker★ 2RoyCampos2025-03-24CandidatePoC-in-GitHub · fourcube/nextjs-middleware-bypass-demoDemo for Next.js middleware bypass - CVE-2025-29927★ 5fourcube2025-03-24CandidatePoC-in-GitHub · iSee857/CVE-2025-29927Next.Js 权限绕过漏洞(CVE-2025-29927)★ 0iSee8572025-03-24CandidatePoC-in-GitHub · Eve-SatOrU/POC-CVE-2025-29927CVE-2025-29927 Proof of Concept★ 3Eve-SatOrU2025-03-24CandidatePoC-in-GitHub · arvion-agent/next-CVE-2025-29927CVE-2025-29927 Authorization Bypass in Next.js Middleware★ 2arvion-agent2025-03-24CandidatePoC-in-GitHub · Oyst3r1ng/CVE-2025-29927Next.js Middleware Auth Bypass★ 2Oyst3r1ng2025-03-24CandidatePoC-in-GitHub · lem0n817/CVE-2025-29927Next.js 中间件授权绕过漏洞测试环境 (CVE-2025-29927)★ 2lem0n8172025-03-24CandidatePoC-in-GitHub · kuzushiki/CVE-2025-29927-testCVE-2025-29927の検証★ 1kuzushiki2025-03-24CandidatePoC-in-GitHub · ricsirigu/CVE-2025-29927A deliberately Next.js app, vulnerable to CVE-2025-29927, Authorization Bypass★ 1ricsirigu2025-03-24CandidatePoC-in-GitHub · 0xWhoknows/CVE-2025-29927Async Python scanner for Next.js CVE-2025-29927. Uses aiohttp & aiofiles to efficiently process large URL lists, detect vulnerabilities, and save results. Features connection pooling, caching, and chunked processing for fast performance★ 30xWhoknows2025-03-24CandidatePoC-in-GitHub · elshaheedy/CVE-2025-29927-Sigma-RuleSigma Rule for CVE-2025–29927 Detection★ 0elshaheedy2025-03-24CandidatePoC-in-GitHub · furmak331/CVE-2025-29927Critical vulnerability in next.js : Bypass middleware authentication★ 0furmak3312025-03-25CandidatePoC-in-GitHub · phoscoder/ghost-routeGhost Route detects if a Next JS site is vulnerable to the corrupt middleware bypass bug (CVE-2025-29927)★ 9phoscoder2025-03-25CandidatePoC-in-GitHub · 0xPb1/Next.js-CVE-2025-29927★ 00xPb12025-03-25CandidatePoC-in-GitHub · jeymo092/cve-2025-29927★ 0jeymo0922025-03-25CandidatePoC-in-GitHub · alihussainzada/CVE-2025-29927-PoCPoC for CVE-2025-29927: Next.js Middleware Bypass Vulnerability. Demonstrates how x-middleware-subrequest can bypass authentication checks. Includes Docker setup for testing.★ 5alihussainzada2025-03-25CandidatePoC-in-GitHub · TheresAFewConors/CVE-2025-29927-TestingPowerShell script to test if a web app is vulnerable to CVE-2025-29927★ 2TheresAFewConors2025-03-25CandidatePoC-in-GitHub · 0xPThree/next.js_cve-2025-29927★ 00xPThree2025-03-25CandidatePoC-in-GitHub · 0xcucumbersalad/cve-2025-29927★ 00xcucumbersalad2025-03-25CandidatePoC-in-GitHub · c0dejump/CVE-2025-29927-checkscript to check cve "CVE-2025-29927" while waiting to add it to HExHTTP★ 3c0dejump2025-03-25CandidatePoC-in-GitHub · maronnjapan/claude-create-CVE-2025-29927★ 0maronnjapan2025-03-25CandidatePoC-in-GitHub · kOaDT/poc-cve-2025-29927This repository contains a proof of concept (POC) and an exploit script for CVE-2025-29927, a critical vulnerability in Next.js that allows attackers to bypass authorization checks implemented in middleware.★ 8kOaDT2025-03-26CandidatePoC-in-GitHub · yugo-eliatrope/test-cve-2025-29927★ 1yugo-eliatrope2025-03-26CandidatePoC-in-GitHub · emadshanab/CVE-2025-29927New nuclei CVE★ 2emadshanab2025-03-26CandidatePoC-in-GitHub · w3shinew/CVE-2025-29927A touch of security★ 0w3shinew2025-03-26CandidatePoC-in-GitHub · aleongx/CVE-2025-29927Next.js Acceso no autorizado CVE-2025-29927★ 0aleongx2025-03-26CandidatePoC-in-GitHub · nicknisi/next-attackA demo of the CVE-2025-29927 vulnerability for a NebraskaJS lightning talk★ 2nicknisi2025-03-26CandidatePoC-in-GitHub · jmbowes/NextSecureScanNext.js CVE-2025-29927 Vulnerability Scanner★ 2jmbowes2025-03-27CandidatePoC-in-GitHub · aleongx/CVE-2025-29927_ScannerEste script verifica la vulnerabilidad CVE-2025-29927 en servidores Next.js, probando múltiples cargas en la cabecera x-middleware-subrequest para detectar accesos no autorizados.★ 0aleongx2025-03-27CandidatePoC-in-GitHub · Nekicj/CVE-2025-29927-exploitnext.js CVE-2025-29927 vulnerability exploit★ 2Nekicj2025-03-27CandidatePoC-in-GitHub · Heimd411/CVE-2025-29927-PoC★ 0Heimd4112025-03-27CandidatePoC-in-GitHub · m2hcz/PoC-for-Next.js-Middleware> 🔓 Proof-of-Concept for a fictional Next.js middleware bypass (CVE-2025-29927) — craft sub-requests to test protected routes.★ 1m2hcz2025-03-27CandidatePoC-in-GitHub · nocomp/CVE-2025-29927-scannerpython script for evaluate if you are vulnerable or not to next.js CVE-2025-29927★ 1nocomp2025-03-27CandidatePoC-in-GitHub · yuzu-juice/CVE-2025-29927_demoThis repository is for educational and research purposes.★ 0yuzu-juice2025-03-28CandidatePoC-in-GitHub · AnonKryptiQuz/NextSploitNextSploit is a command-line tool designed to detect and exploit CVE-2025-29927, a security flaw in Next.js★ 92AnonKryptiQuz2025-03-28CandidatePoC-in-GitHub · w2hcorp/CVE-2025-29927-PoCHere is a simple but effective exploit for CVE-2025-29927.★ 1w2hcorp2025-03-29CandidatePoC-in-GitHub · ferpalma21/Automated-Next.js-Security-Scanner-for-CVE-2025-29927This script scans a list of URLs to detect if they are using **Next.js** and determines whether they are vulnerable to **CVE-2025-29927**. It optionally attempts exploitation using a wordlist.★ 2ferpalma212025-03-29CandidatePoC-in-GitHub · dante01yoon/CVE-2025-29927Next.js CVE-2025-29927 demonstration★ 0dante01yoon2025-03-29CandidatePoC-in-GitHub · ayato-shitomi/WebLab_CVE-2025-29927Next.js Auth Bypass Lab ‐ CVE-2025-29927★ 0ayato-shitomi2025-03-30CandidatePoC-in-GitHub · Kamal-418/Vulnerable-Lab-NextJS-CVE-2025-29927★ 1Kamal-4182025-03-30CandidatePoC-in-GitHub · Ev3rPalestine/0xMiddlewareCVE-2025-29927: Next.js Middleware Exploit★ 0Ev3rPalestine2025-03-30CandidatePoC-in-GitHub · dedibagus/cve-2025-29927-pocAuthorization Bypass in Next.js Middleware★ 0dedibagus2025-04-01CandidatePoC-in-GitHub · alastair66/CVE-2025-29927Next.js Middleware Bypass Vulnerability★ 1alastair662025-04-01CandidatePoC-in-GitHub · 0xb1lal/CVE-2025-29927Next.js CVE-2025-29927 güvenlik açığı hakkında★ 00xb1lal2025-04-01CandidatePoC-in-GitHub · JOOJIII/CVE-2025-29927★ 0JOOJIII2025-04-01CandidatePoC-in-GitHub · Naveen-005/Next.Js-middleware-bypass-vulnerability-CVE-2025-29927A basic proof of concept of the CVE-2025-29927 vulnerability that allows to bypass the middleware scripts.★ 0Naveen-0052025-04-02CandidatePoC-in-GitHub · Gokul-Krishnan-V-R/cve-2025-29927Next.js and the corrupt middleware...TRY TO HACK IT..!★ 0Gokul-Krishnan-V-R2025-04-02CandidatePoC-in-GitHub · fahimalshihab/NextBypassNext.js Middleware Authorization Bypass Tool (CVE-2025-29927)★ 0fahimalshihab2025-04-03CandidatePoC-in-GitHub · all3njk/NextJS_CVE-2025-29927★ 0all3njk2025-04-04CandidatePoC-in-GitHub · Balajih4kr/cve-2025-29927CVE-2025-29927 is a critical vulnerability in Next.js, a popular React-based web framework. The flaw exists in how the middleware feature handles certain internal headers — specifically, the x-middleware-subrequest header★ 0Balajih4kr2025-04-05CandidatePoC-in-GitHub · YEONDG/nextjs-cve-2025-29927vulnerable-nextjs-14-CVE-2025-29927★ 0YEONDG2025-04-06CandidatePoC-in-GitHub · gotr00t0day/CVE-2025-29927Next.js Middleware Bypass Scanne★ 8gotr00t0day2025-04-06CandidatePoC-in-GitHub · pixilated730/NextJS-Exploit-CVE-2025-29927★ 1pixilated7302025-04-07CandidatePoC-in-GitHub · ValGrace/middleware-auth-bypassCVE-2025-29927 ~ a poc of the next.js middleware authentication bypass★ 0ValGrace2025-04-08CandidatePoC-in-GitHub · 0xnxt1me/CVE-2025-29927★ 10xnxt1me2025-04-08CandidatePoC-in-GitHub · pickovven/vulnerable-nextjs-14-CVE-2025-29927★ 0pickovven2025-04-08CandidatePoC-in-GitHub · l1uk/nextjs-middleware-exploitResearch on Next.js middleware vulnerability (CVE-2025-29927) allowing authorization bypass and potential exploits.★ 0l1uk2025-04-09CandidatePoC-in-GitHub · darklotuskdb/nextjs-CVE-2025-29927-hunterNext.js CVE-2025-29927 Hunter★ 0darklotuskdb2025-04-11CandidatePoC-in-GitHub · ethanol1310/POC-CVE-2025-29927-POC CVE-2025-29927★ 0ethanol13102025-04-13CandidatePoC-in-GitHub · UNICORDev/exploit-CVE-2025-29927Exploit for CVE-2025-29927 (Next.js) - Authorization Bypass★ 14UNICORDev2025-04-14CandidatePoC-in-GitHub · Knotsecurity/CVE-2025-29927-NextJs-Middleware-SimulationSimulates CVE-2025-29927, a critical Next.js vulnerability allowing attackers to bypass middleware authorization by exploiting the internal x-middleware-subrequest HTTP header. Demonstrates unauthorized access to protected routes and provides mitigation strategies.★ 0Knotsecurity2025-04-16CandidatePoC-in-GitHub · mhamzakhattak/CVE-2025-29927★ 1mhamzakhattak2025-04-16CandidatePoC-in-GitHub · enochgitgamefied/NextJS-CVE-2025-29927★ 0enochgitgamefied2025-04-16CandidatePoC-in-GitHub · Grand-Moomin/Vuln-Next.js-CVE-2025-29927★ 0Grand-Moomin2025-04-18CandidatePoC-in-GitHub · pouriam23/Next.js-Middleware-Bypass-CVE-2025-29927-★ 2pouriam232025-04-21CandidatePoC-in-GitHub · kh4sh3i/CVE-2025-29927CVE-2025-29927: Next.js Middleware Bypass Vulnerability★ 2kh4sh3i2025-04-23CandidatePoC-in-GitHub · EQSTLab/CVE-2025-29927Next.js middleware bypass exploit★ 2EQSTLab2025-04-25CandidatePoC-in-GitHub · Hirainsingadia/CVE-2025-29927Next js middlewareauth Bypass★ 0Hirainsingadia2025-04-28CandidatePoC-in-GitHub · HoumanPashaei/CVE-2025-29927This is a CVE-2025-29927 Scanner.★ 5HoumanPashaei2025-04-29CandidatePoC-in-GitHub · rubbxalc/CVE-2025-29927★ 1rubbxalc2025-04-29CandidatePoC-in-GitHub · olimpiofreitas/CVE-2025-29927-scanner★ 1olimpiofreitas2025-05-03CandidatePoC-in-GitHub · moften/CVE-2025-29927_Next.js_Auth_BypassNext.js Auth Bypass PoC Edge Runtime Env Leak via Middleware Bug★ 1moften2025-05-06CandidatePoC-in-GitHub · EarthAngel666/x-middleware-exploitx-middleware exploit for next.js CVE-2023–46298 cache poisoning and CVE-2025-29927 bypass★ 0EarthAngel6662025-05-08CandidatePoC-in-GitHub · lstudlo/nextjs-cve-demo演示 Next.js 中的 Middleware 授權繞過漏洞 (CVE-2025-29927) 允許未經授權的用戶存取受保護的資訊。★ 2lstudlo2025-05-15CandidatePoC-in-GitHub · enochgitgamefied/NextJS-CVE-2025-29927-Docker-Lab★ 0enochgitgamefied2025-05-23CandidatePoC-in-GitHub · sagsooz/CVE-2025-29927🔐 Python-based smart scanner for CVE-2025-29927 — Next.js middleware authentication bypass vulnerability. Detects meta refresh, keyword-based redirects, and more.★ 0sagsooz2025-05-26CandidatePoC-in-GitHub · SugiB3o/vulnerable-nextjs-14-CVE-2025-29927vulnerable-nextjs-14-CVE-2025-29927★ 0SugiB3o2025-05-29CandidatePoC-in-GitHub · amitlttwo/Next.JS-CVE-2025-29927★ 0amitlttwo2025-06-12CandidatePoC-in-GitHub · kazuya256/next-js-auth-bypass🔓 Next.js Auth Bypass Demo - Educational application demonstrating CVE-2025-29927 middleware authentication bypass vulnerability . ⚠️ For educational use only.[Made using Ai]★ 1kazuya2562025-07-06CandidatePoC-in-GitHub · mickhacking/Thank-u-NextCVE-2025-29927 PoC | Auth Bypass Exploit | Python Tool using httpx | Middleware Vulnerability | Ethical Hacking Toolkit★ 0mickhacking2025-07-14CandidatePoC-in-GitHub · b4sh0xf/PoC-CVE-2025-29927→ poc for CVE-2025-29927★ 0b4sh0xf2025-07-29CandidatePoC-in-GitHub · rgvillanueva28/vulnbox-easy-CVE-2025-29927★ 0rgvillanueva282025-07-30CandidatePoC-in-GitHub · s11s11/CVE-2025-29927Demo of CVE-2025-29927 for secure programming class★ 0s11s112025-08-17CandidatePoC-in-GitHub · R3verseIN/Nextjs-middleware-vulnerable-appdemo-CVE-2025-29927★ 0R3verseIN2025-08-19CandidatePoC-in-GitHub · zs1n/CVE-2025-29927PoC | NextJS Middleware 15.2.2 - Authorization Bypass★ 0zs1n2025-08-28CandidatePoC-in-GitHub · MKIRAHMET/CVE-2025-29927-PoCThis repository contains **research and analysis** related to CVE-2025-29927. It demonstrates safe, controlled testing approaches for a path traversal/middleware misconfiguration vulnerability in web applications.★ 0MKIRAHMET2025-09-11CandidatePoC-in-GitHub · adjscent/vulnerable-nextjs-14-CVE-2025-29927do not use. vulnerable★ 0adjscent2025-09-17CandidatePoC-in-GitHub · sdrtba/CVE-2025-29927★ 0sdrtba2025-09-20CandidatePoC-in-GitHub · iteride/CVE-2025-29927★ 1iteride2025-09-21CandidatePoC-in-GitHub · sermikr0/nextjs-middleware-auth-bypassCVE-2025-29927★ 1sermikr02025-09-23CandidatePoC-in-GitHub · amalpvatayam67/day10-nextjs-middleware-labNext.js middleware auth-bypass lab (CVE-2025-29927 simulation)★ 0amalpvatayam672025-09-23CandidatePoC-in-GitHub · diogolourencodev/middleforceSimple script to attempt a Bypass on a server possibly vulnerable to CVE-2025-29927 (Next.js Middleware)★ 1diogolourencodev2025-10-04CandidatePoC-in-GitHub · Bongni/CVE-2025-29927Reproduction and fix of the CVE-2025-29927 vulnerability.★ 1Bongni2025-10-08CandidatePoC-in-GitHub · NS-Projects-Unina/CTF_CVE_DSP_1Una CTF, in formato DSP-compliant, basata sulla CVE-2025-29927 di nextjs.★ 0NS-Projects-Unina2025-10-15CandidatePoC-in-GitHub · lucaschanzx/CVE-2025-29927-PoC★ 0lucaschanzx2025-10-27CandidatePoC-in-GitHub · liamromanis101/CVE-2025-29927-NextJSPoC for testing CVE-2025-29927 for Next.js versions 11.x, 12.x <= 12.3.5, 13.x <= 13.5.9, 14.x <=14.2.25, 15.x <= 15.2.3★ 1liamromanis1012025-12-02CandidatePoC-in-GitHub · DanielHallbro/CVE-2025-29927-Nextjs-Bypass-PoCA Proof of Concept for CVE-2025-29927 demonstrating a middleware bypass in Next.js versions prior to 13.5.9★ 1DanielHallbro2026-01-26CandidatePoC-in-GitHub · Si-Ni/CVE-2025-29927-Proof-of-ConceptCapture the Flag challenge: CVE-2025-29927 in combination with a command injection vulnerability★ 0Si-Ni2026-02-01CandidatePoC-in-GitHub · sangrok-jeon/CVE-2025-29927-Nextjs-AnalysisCVE-2025-29927-Nextjs 분석 보고서★ 1sangrok-jeon2026-03-17CandidatePoC-in-GitHub · Toddkk02/CVE-2025-29927★ 0Toddkk022026-03-17CandidatePoC-in-GitHub · hujiaozhuzhu/CVE-2025-29927__Next.jsCVE-2025-29927 - Next.js漏洞测试工具★ 0hujiaozhuzhu2026-04-02CandidatePoC-in-GitHub · metasploit403/cve-2025-29927-labDeliberately vulnerable Next.js application demonstrating CVE-2025-29927 (middleware-based auth bypass) for learning and bug bounty practice.★ 0metasploit4032026-04-02CandidatePoC-in-GitHub · shahin-shadow/nextjs-auth-bypassAnalysis and exploitation of a Next.js authorization bypass vulnerability (CVE-2025-29927)★ 0shahin-shadow2026-04-04CandidatePoC-in-GitHub · TheWaterbug/alpr-dashboard-patchesRuntime patches for algertc/alpr-dashboard: async logger fix and CVE-2025-29927 nginx mitigation★ 0TheWaterbug2026-04-24CandidatePoC-in-GitHub · Nayekah/Next.js-Proof-of-ConceptSome Proof-of-Concept (POCs) for CVE-2025-29927, CVE-2026-27978, and CVE-2026-29057 in Next.js.★ 0Nayekah2026-04-25CandidatePoC-in-GitHub · bk-security/auth-header-trust-rulesSemgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.★ 0bk-security2026-05-12CandidatePoC-in-GitHub · gitgudKrish/cve-2025-29927-nextjs★ 0gitgudKrish2026-05-20CandidatePoC-in-GitHub · SwapnilDeshpande/cve-2025-29927-labReproduction lab for CVE-2025-29927 — Next.js middleware authorization bypass (CVSS 9.1)★ 0SwapnilDeshpande2026-06-10CandidatePoC-in-GitHub · Fomovet/cve-2025-29927POC for CVE-2025-29927★ 0Fomovet2026-06-21CandidatePoC-in-GitHub · berraesen/nextjs-middleware-auth-bypass-labBu laboratuvar ortamını sıfırdan kendim oluşturdum. Next.js uygulaması içerisinde giriş, ana sayfa ve admin sayfalarını hazırladım. Middleware ile yetkilendirme mekanizmasını kurduktan sonra Burp Suite kullanarak CVE-2025-29927 zafiyetini kontrollü ortamda gösterdim.★ 1berraesen2026-08-03CandidatePoC-in-GitHub · kuyrathdaro/cve-2025-29927★ 0kuyrathdaro2026-08-29CandidatePoC-in-GitHub · Ritinify/CVE-2025-29927-PoC★ 0Ritinify2026-09-05CandidateSploitusProof-of-concept exploit for CVE-2025-29927. CVSS 9.1.Sploitus index2026-09-05T12:41:19+00:00Candidate