CVE-2025-29927
by f4b52 - Monday March 24, 2025 at 04:54 PM
#1
Next.js uses an internal header x-middleware-subrequest to prevent recursive requests from triggering infinite loops. The security vulnerability shows it's possible to skip running Middleware, which could allow requests to bypass critical checks—such as authorization cookie validation—before reaching routes.

Hidden Content
You must register or login to view this content.
Reply
#2
i think john hammond did a video on this cve  ?

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#3
(Mar 24, 2025, 04:54 PM)f4b52 Wrote: Next.js uses an internal header x-middleware-subrequest to prevent recursive requests from triggering infinite loops. The security vulnerability shows it's possible to skip running Middleware, which could allow requests to bypass critical checks—such as authorization cookie validation—before reaching routes.
yes we look this comment
Reply
#4
lool, thx for share this cve
Reply
#5
Can't wait to check the impact of this one on some next.js applications
thanks for sharing
Reply
#6
thx share. best sharing
Reply
#7
thank you so much forr this
Reply
#8
Thank you for sharing this CVE with us
Reply
#9
Thank you for sharing this CVE with us
Reply
#10
thanks for sharing
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  {SECRET} DATABASE OF EXPLOITS lulagain 434 25,925 Yesterday, 01:40 PM
Last Post: rootofhunter
  New Zer0 Day Wordpress A3g00n 79 3,077 Apr 30, 2026, 04:09 PM
Last Post: baku
  new wordpress website takeover vuln (video + poc ) zinzeur 314 28,181 Apr 30, 2026, 03:54 PM
Last Post: baku
  Google Dorks for finding SQL injection vulnerabilities and other security issues 1yush 66 3,082 Apr 29, 2026, 08:51 PM
Last Post: Yjuddur
  Acunetix Premium Cracked v24 Full Activated A3g00n 22 1,387 Apr 29, 2026, 09:22 AM
Last Post: Usercomplex

Forum Jump:


 Users browsing this forum: 1 Guest(s)