People

CVE-2025-29927: Next.js Middleware Authorization Bypass

offsec.com

In this CVE blog, we explore a vulnerability in Next.js stemming from the improper trust of the x-middleware-subrequest header.

Visit Site

People offsec.com

CVE-2025-29927: Next.js Middleware Authorization Bypass
PeopleCVE-2025-27636 – Remote Code Execution in Apache Camel via Case-Sensitive Header Filtering Bypassoffsec.com PeopleCVE-2025-30208 – Vite Arbitrary File Read via @fs Path Traversal Bypassoffsec.com PeopleCVE-2025-32433: Vulnerability in Erlang/OTP SSH Implementationoffsec.com PeopleCVE-2025-23211: Tandoor Recipes Jinja2 SSTI to Remote Code Executionoffsec.com PeopleCVE-2025-0655 – Remote Code Execution in D-Tale via Unprotected Custom Filtersoffsec.com PeopleCVE-2025-3248 – Unauthenticated Remote Code Execution in Langflow via Insecure Python exec Usageoffsec.com EventsMore Than Protection: How SMBs Can Build Cybersecurity for What’s NextBrightTALK Products & ServicesThe DeepL API for translation and writing improvement at scaledeepl.com BlogsI'm Doing a Little Consulting — overreactedoverreacted.io ResourcesQuack Remote Protocolduckdb.org ResourcesInterval Typeduckdb.org ResourcesInterval Typeduckdb.org ResourcesInterval Typeduckdb.org ResourcesInterval Typeduckdb.org ResourcesInterval Typeduckdb.org ResourcesInterval Typeduckdb.org ResourcesInterval Typeduckdb.org ResourcesBuild a User Management App with Next.jssupabase.com ResourcesUse Supabase with Next.jssupabase.com ResourcesPostgreSQL Extension Functionsduckdb.org