CVE-2025-29927
JavaScript Análise e mitigação de vulnerabilidades

Visão geral

Next.js, a React framework for building full-stack web applications, disclosed a critical security vulnerability (CVE-2025-29927) that affects versions prior to 14.2.25 and 15.2.3. The vulnerability was discovered on February 27, 2025, and publicly disclosed on March 21, 2025. This security flaw affects self-hosted Next.js applications using middleware with 'next start' and 'output: standalone' configurations (GitHub Advisory, Next.js Blog).

Detalhes técnicos

The vulnerability stems from the improper handling of an internal header 'x-middleware-subrequest' which Next.js uses to prevent recursive requests from triggering infinite loops. When this header is included in requests to protected routes, Next.js incorrectly allows the request to bypass middleware execution entirely, potentially circumventing critical security checks. The vulnerability has been assigned a CVSS v3.1 score of 9.1 (Critical) with a vector string of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, indicating high severity with potential for unauthorized access and data modification (JFrog Blog, GitHub Advisory).

Impacto

The vulnerability can lead to authorization bypass in applications that rely on middleware for security checks. If successfully exploited, attackers could bypass authentication mechanisms, access protected routes, and potentially gain unauthorized access to sensitive information. In some cases, the vulnerability could also lead to cache poisoning and denial of service conditions (Rapid7 Blog, JFrog Blog).

Exploração

The vulnerability is relatively straightforward to exploit, requiring only the addition of the x-middleware-subrequest header to HTTP requests when accessing protected resources. The exploitation doesn't require special privileges or user interaction, making it particularly dangerous. However, applications hosted on Vercel or Netlify, as well as those deployed as static exports, are not affected by this vulnerability (GitHub Advisory, Hacker News).

Mitigação e soluções alternativas

The vulnerability has been patched in versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3. If upgrading is not immediately possible, organizations can implement a workaround by preventing external user requests containing the x-middleware-subrequest header from reaching their Next.js application. This can be achieved through web server configurations or Web Application Firewall (WAF) rules. Cloudflare users can enable a managed WAF rule for protection (GitHub Advisory, JFrog Blog).

Reações da comunidade

The vulnerability has garnered significant attention in the security community, with multiple security firms and researchers publishing detailed analyses. Next.js has acknowledged that while they published the CVE promptly, they 'missed the mark on partner communications' and are establishing a partner mailing list to improve future vulnerability communications (OSS Security).

Recursos adicionais


OrigemEste relatório foi gerado usando IA

Relacionado JavaScript Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

CVE-2026-71476HIGH8.7
  • JavaScript logoJavaScript
  • @nx/gcs-cache
NãoSimAug 06, 2026
CVE-2026-71437MEDIUM6.5
  • JavaScript logoJavaScript
  • node-mermaid
NãoSimAug 06, 2026
CVE-2026-71439MEDIUM5.3
  • JavaScript logoJavaScript
  • mermaid
NãoSimAug 06, 2026
CVE-2026-71498MEDIUM5.1
  • JavaScript logoJavaScript
  • re2
NãoSimAug 06, 2026
CVE-2026-71438LOW2.4
  • JavaScript logoJavaScript
  • mermaid
NãoSimAug 06, 2026

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adam FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades