Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware. If patching to a safe version is infeasible, it is recommend that you prevent external user requests which contain the x-middleware-subrequest header from reaching your Next.js application. This vulnerability is fixed in 12.3.5, 13.5.9, 14.2.25, and 15.2.3.
PoC: CVE-2025-29927
This is a CVE-2025-29927 Scanner.
PoC: CVE-2025-29927-Next.js-Middleware-Authorization-Bypass
CVE‑2025‑29927 is a critical vulnerability (CVSS 9.1) in Next.js that allows attackers to bypass middleware‑based security checks.
PoC: nextjs-cve-demo
演示 Next.js 中的 Middleware 授權繞過漏洞 (CVE-2025-29927) 允許未經授權的用戶存取受保護的資訊。
PoC: exploit-CVE-2025-29927
Exploit for CVE-2025-29927 (Next.js) - Authorization Bypass
PoC: nextjs-CVE-2025-29927-hunter
Next.js CVE-2025-29927 Hunter
PoC: CVE-2025-29927
Next.js Middleware Bypass Scanne
PoC: CVE-2025-29927-Research
CVE-2025-29927에 대한 설명 및 리서치
PoC: CVE-2025-29927
New nuclei CVE
PoC: ghost-route
Ghost Route detects if a Next JS site is vulnerable to the corrupt middleware bypass bug (CVE-2025-29927)
PoC: CVE-2025-29927
Async Python scanner for Next.js CVE-2025-29927. Uses aiohttp & aiofiles to efficiently process large URL lists, detect vulnerabilities, and save results. Features connection pooling, caching, and chunked processing for fast performance
PoC: CVE-2025-29927
Next.js 中间件授权绕过漏洞测试环境 (CVE-2025-29927)
PoC: CVE-2025-29927
New nuclei CVE
PoC: CVE-2025-29927
Next.js Middleware Auth Bypass
PoC: POC-CVE-2025-29927
CVE-2025-29927 Proof of Concept
[POC] GHSA-3mgp-fx93-9xv5 — cve-2025-29927
POC for CVE-2025-29927
PoC: nextjs-middleware-auth-bypass-lab
Bu laboratuvar ortamını sıfırdan kendim oluşturdum. Next.js uygulaması içerisinde giriş, ana sayfa ve admin sayfalarını hazırladım. Middleware ile yetkilendirme mekanizmasını kurduktan sonra Burp Suite kullanarak CVE-2025-29927 zafiyetini kontrollü ortamda gösterdim.
PoC: cve-2025-29927-lab
Reproduction lab for CVE-2025-29927 — Next.js middleware authorization bypass (CVSS 9.1)
PoC: auth-header-trust-rules
Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.
PoC: Next.js-Proof-of-Concept
Some Proof-of-Concept (POCs) for CVE-2025-29927, CVE-2026-27978, and CVE-2026-29057 in Next.js.
PoC: alpr-dashboard-patches
Runtime patches for algertc/alpr-dashboard: async logger fix and CVE-2025-29927 nginx mitigation
PoC: nextjs-auth-bypass
Analysis and exploitation of a Next.js authorization bypass vulnerability (CVE-2025-29927)
PoC: cve-2025-29927-lab
Deliberately vulnerable Next.js application demonstrating CVE-2025-29927 (middleware-based auth bypass) for learning and bug bounty practice.
PoC: CVE-2025-29927__Next.js
CVE-2025-29927 - Next.js漏洞测试工具
PoC: CVE-2025-29927-Nextjs-Analysis
CVE-2025-29927-Nextjs 분석 보고서
PoC: CVE-2025-29927-Proof-of-Concept
Capture the Flag challenge: CVE-2025-29927 in combination with a command injection vulnerability
PoC: CVE-2025-29927-Nextjs-Bypass-PoC
A Proof of Concept for CVE-2025-29927 demonstrating a middleware bypass in Next.js versions prior to 13.5.9
PoC: bughunter-cyber-intel-dashboard
Interactive cybersecurity threat intelligence dashboard with 5 critical vulnerabilities, CVSS scoring, exploitation analysis, and bug bounty hunting guides (TE.0, CVE-2025-29927, Shadow AI, Kimwolf, LastPass)
PoC: CVE-2025-29927-NextJS
PoC for testing CVE-2025-29927 for Next.js versions 11.x, 12.x <= 12.3.5, 13.x <= 13.5.9, 14.x <=14.2.25, 15.x <= 15.2.3
PoC: CTF_CVE_DSP_1
Una CTF, in formato DSP-compliant, basata sulla CVE-2025-29927 di nextjs.
PoC: CVE-2025-29927
Reproduction and fix of the CVE-2025-29927 vulnerability.
PoC: middleforce
Simple script to attempt a Bypass on a server possibly vulnerable to CVE-2025-29927 (Next.js Middleware)
PoC: day10-nextjs-middleware-lab
Next.js middleware auth-bypass lab (CVE-2025-29927 simulation)
PoC: nextjs-middleware-auth-bypass
CVE-2025-29927
PoC: vulnerable-nextjs-14-CVE-2025-29927
do not use. vulnerable
PoC: CVE-2025-29927-PoC
This repository contains **research and analysis** related to CVE-2025-29927. It demonstrates safe, controlled testing approaches for a path traversal/middleware misconfiguration vulnerability in web applications.
PoC: CVE-2025-29927
PoC | NextJS Middleware 15.2.2 - Authorization Bypass
PoC: CVE-2025-29927
Demo of CVE-2025-29927 for secure programming class
PoC: PoC-CVE-2025-29927
→ poc for CVE-2025-29927
PoC: CVE-2025-29927
The POC for m6.fr website
PoC: Thank-u-Next
CVE-2025-29927 PoC | Auth Bypass Exploit | Python Tool using httpx | Middleware Vulnerability | Ethical Hacking Toolkit
PoC: thank-u-next
CVE-2025-29927 PoC | Auth Bypass Exploit | Python Tool using httpx | Middleware Vulnerability | Ethical Hacking Toolkit
PoC: next-js-auth-bypass
🔓 Next.js Auth Bypass Demo - Educational application demonstrating CVE-2025-29927 middleware authentication bypass vulnerability . ⚠️ For educational use only.
PoC: Blackash-CVE-2025-29927
CVE-2025-29927
PoC: vulnerable-nextjs-14-CVE-2025-29927
vulnerable-nextjs-14-CVE-2025-29927
PoC: CVE-2025-29927
🔐 Python-based smart scanner for CVE-2025-29927 — Next.js middleware authentication bypass vulnerability. Detects meta refresh, keyword-based redirects, and more.
PoC: x-middleware-exploit
x-middleware exploit for next.js CVE-2023–46298 cache poisoning and CVE-2025-29927 bypass
PoC: CVE-2025-29927
Next.js Auth Bypass PoC Edge Runtime Env Leak via Middleware Bug
PoC: CVE-2025-29927
CVE-2025-29927
PoC: CVE-2025-29927
Next js middlewareauth Bypass
PoC: CVE-2025-29927
Next.js middleware bypass exploit
PoC: CVE-2025-29927
CVE-2025-29927: Next.js Middleware Bypass Vulnerability
PoC: CVE-2025-29927-NextJs-Middleware-Simulation
Simulates CVE-2025-29927, a critical Next.js vulnerability allowing attackers to bypass middleware authorization by exploiting the internal x-middleware-subrequest HTTP header. Demonstrates unauthorized access to protected routes and provides mitigation strategies.
PoC: POC-CVE-2025-29927-
POC CVE-2025-29927
PoC: nextjs-middleware-exploit
Research on Next.js middleware vulnerability (CVE-2025-29927) allowing authorization bypass and potential exploits.
PoC: middleware-auth-bypass
CVE-2025-29927 ~ a poc of the next.js middleware authentication bypass
PoC: NextJS-Exploit-
CVE-2025-29927
PoC: nextjs-cve-2025-29927
vulnerable-nextjs-14-CVE-2025-29927
PoC: cve-2025-29927
CVE-2025-29927 is a critical vulnerability in Next.js, a popular React-based web framework. The flaw exists in how the middleware feature handles certain internal headers — specifically, the x-middleware-subrequest header
PoC: NextBypass
Next.js Middleware Authorization Bypass Tool (CVE-2025-29927)
PoC: cve-2025-29927
Next.js and the corrupt middleware
PoC: Next.Js-middleware-bypass-vulnerability-CVE-2025-29927
A basic proof of concept of the CVE-2025-29927 vulnerability that allows to bypass the middleware scripts.
PoC: CVE-2025-29927
Next.js CVE-2025-29927 güvenlik açığı hakkında
PoC: CVE-2025-29927
Next.js Middleware Bypass Vulnerability
PoC: cve-2025-29927-poc
Authorization Bypass in Next.js Middleware
PoC: CVE-2025-29927
CVE-2025-29927 Bypass Authorization Next.js
PoC: 0xMiddleware
CVE-2025-29927: Next.js Middleware Exploit
PoC: WebLab_CVE-2025-29927
Next.js Auth Bypass Lab ‐ CVE-2025-29927
PoC: CVE-2025-29927
Next.js CVE-2025-29927 demonstration
PoC: Automated-Next.js-Security-Scanner-for-CVE-2025-29927
This script scans a list of URLs to detect if they are using **Next.js** and determines whether they are vulnerable to **CVE-2025-29927**. It optionally attempts exploitation using a wordlist.
PoC: CVE-2025-29927-Exploit
Here is a simple but effective exploit for CVE-2025-29927.
PoC: NextSploit
NextSploit is a command-line tool designed to detect and exploit CVE-2025-29927, a security flaw in Next.js
PoC: 0xMiddleware
CVE-2025-29927: Next.js Middleware Exploit
PoC: CVE-2025-29927_demo
This repository is for educational and research purposes.
PoC: CVE-2025-29927-scanner
python script for evaluate if you are vulnerable or not to next.js CVE-2025-29927
PoC: PoC-for-Next.js-Middleware
> 🔓 Proof-of-Concept for a fictional Next.js middleware bypass (CVE-2025-29927) — craft sub-requests to test protected routes.
PoC: CVE-2025-29927-exploit
how to hack 90% of next.js created websites with CVE-2025-29927 vulnerability exploit
PoC: CVE-2025-29927_Scanner
Este script verifica la vulnerabilidad CVE-2025-29927 en servidores Next.js, probando múltiples cargas en la cabecera x-middleware-subrequest para detectar accesos no autorizados.
PoC: Automated-Next.js-Security-Scanner-for-CVE-2025-29927
This script checks if a given website running Next.js is vulnerable to CVE-2025-29927, a critical middleware bypass vulnerability.
PoC: NextSecureScan
Next.js CVE-2025-29927 Vulnerability Scanner
PoC: next-attack
A demo of the CVE-2025-29927 vulnerability for a NebraskaJS lightning talk
PoC: CVE-2025-29927
Next.js Acceso no autorizado CVE-2025-29927
PoC: CVE-2025-29927
A touch of security
PoC: poc-cve-2025-29927
This repository contains a proof of concept (POC) and an exploit script for CVE-2025-29927, a critical vulnerability in Next.js that allows attackers to bypass authorization checks implemented in middleware.
PoC: CVE-2025-29927-check
script to check cve "CVE-2025-29927" while waiting to add it to HExHTTP
PoC: CVE-2025-29927-Testing
Script to test if a web app is vulnerable to CVE-2025-29927
PoC: CVE-2025-29927-PoC
PoC for CVE-2025-29927: Next.js Middleware Bypass Vulnerability. Demonstrates how x-middleware-subrequest can bypass authentication checks. Includes Docker setup for testing.
PoC: CVE-2025-29927
Critical vulnerability in next.js : Bypass middleware authentication
PoC: CVE-2025-29927-Sigma-Rule
Sigma Rule for CVE-2025–29927 Detection
PoC: CVE-2025-29927-POC
Nuclei Template: CVE-2025-29927 - Next.js Middleware Authentication Bypass
PoC: CVE-2025-29927
A deliberately Next.js app, vulnerable to CVE-2025-29927, Authorization Bypass
PoC: CVE-2025-29927-test
CVE-2025-29927の検証
PoC: next-CVE-2025-29927
CVE-2025-29927 Authorization Bypass in Next.js Middleware
PoC: CVE-2025-29927
Next.Js 权限绕过漏洞(CVE-2025-29927)
PoC: nextjs-middleware-bypass-demo
Demo for Next.js middleware bypass - CVE-2025-29927
PoC: CVE-2025-29927
CVE-2025-29927 Exploit Checker
PoC: nextjs-vulnerable-app
CVE-2025-29927 lab
PoC: CVE-2025-29927-POC
Authorization Bypass in Next.js Middleware
PoC: CVE-2025-29927-PoC-Exploit
Proof-of-Concept for Authorization Bypass in Next.js Middleware
PoC: cve-2025-29927-demo
Next.js における認可バイパスの脆弱性を再現するデモです。
PoC: CVE-2025-29927
CVE-2025-29927 Proof of Concept
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free