Zum Hauptinhalt springen
•••
AI & KI NachrichtenGoogle Tests Plan for A.I. Data Centers in Space(03.10.2026 um 01:46 Uhr)
•
Admin & Dev ToolsGitHub Release: can1357/oh-my-pi v18.5.0 (03.10.2026)(03.10.2026 um 02:10 Uhr)
•••
Sichere ProgrammierungCross-Chain Bridge Risk Assessment: Bitkub(03.10.2026 um 01:41 Uhr)
••••••
AI & KI NachrichtenGoogle Tests Plan for A.I. Data Centers in Space(03.10.2026 um 01:46 Uhr)
•
Admin & Dev ToolsGitHub Release: can1357/oh-my-pi v18.5.0 (03.10.2026)(03.10.2026 um 02:10 Uhr)
•••
Sichere ProgrammierungCross-Chain Bridge Risk Assessment: Bitkub(03.10.2026 um 01:41 Uhr)
•••
Intelligence View
⚡ tsecurity.de Intelligence

CVE-2025-29927: How a Header Bypass in Next.js Broke Auth for Some AI Apps

About Author Hi, I'm Sharon, a product manager at Chaitin Tech. We build SafeLine, an open-source Web Application Firewall built for real-world threats. While…

Beitrag
0
Seite
0
↗ Quelle (dev.to)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!

About Author




Hi, I'm Sharon, a product manager at Chaitin Tech. We build SafeLine, an open-source Web Application Firewall built for real-world threats. While SafeLine focuses on HTTP-layer protection, our emergency response center monitors and responds to RCE and authentication vulnerabilities across the stack to help developers stay safe.






A logic flaw in Next.js middleware exposes protected routes in major AI applications. Here's what happened—and how to fix it.



Next.js, the full-stack web framework developed by Vercel, powers many modern SSR/SSG and Edge Function apps. But in March 2025, a critical vulnerability (CVE-2025-29927) was publicly disclosed—affecting authentication and security middleware in real-world deployments.






Vulnerability Summary



The issue lies in how Next.js middleware handles a special internal request header: x-middleware-subrequest.



Originally designed for internal use only, this header was not properly validated—allowing attackers to spoof it in external requests. As a result, authentication logic, redirects, or other security-related middleware could be silently bypassed.



This flaw is especially dangerous for apps using Edge Middleware (enabled by default) to protect routes such as admin panels or APIs. Researchers at Chaitin Tech confirmed the bug could affect several popular AI-powered web applications.






Root Cause



Next.js trusted the presence of x-middleware-subrequest without verifying its origin.



By injecting this header manually, attackers can trick the framework into skipping middleware execution, effectively bypassing logic that enforces authentication, permissions, or headers like CSP.






Conditions for Exploitation




  • App uses Next.js middleware for auth, redirects, or request filtering.

  • Middleware runs in Edge Function mode (default in recent versions).

  • External requests can include custom headers.






Impact





  • Auth Bypass: Attackers gain access to protected pages or APIs (e.g., admin dashboards, user data).


  • Security Controls Bypassed: Middleware-defined CSP, header injection, or other filters can be skipped, increasing risk of XSS or similar attacks.


  • No User Interaction Needed: Exploitable remotely, without login or user clicks.
































Risk Level HIGH
Attack Vector Remote / Network
Auth Required None
Affected Config Default (Edge on)
Exploit Maturity POC Public
Fix Complexity Low (patch available)





Affected Versions



The bug affects the following Next.js versions:





  • 11.1.4 to 13.5.6


  • 14.0.0 to 14.2.24


  • 15.0.0 to 15.2.2






Fixed in:




  • 14.2.25

  • 15.2.3






How to Fix It






Upgrade Now



If you're using one of the vulnerable versions, update to a patched version immediately:




npm install [email protected]
# or
npm install [email protected]









Temporary Mitigation



If immediate upgrade isn't possible, apply these workarounds:





  • Strip the Header: Use a reverse proxy (e.g., Nginx) to remove x-middleware-subrequest from all external requests.


  • Filter at CDN/WAF: Block or sanitize this header at the gateway level.






Reproduction



Researchers have publicly released a working POC showing how to exploit the bug by sending crafted requests with the forged header.



Image description






Timeline





  • Mar 23, 2025: Vulnerability publicly disclosed


  • Mar 23, 2025: Chaitin Security Lab reproduced the exploit


  • Mar 24, 2025: Emergency advisory released by Chaitin






References








Join the SafeLine Community









Stay secure. Always verify what headers you're trusting—and never assume they're safe just because they exist.


Cyber Threat Intelligence & Forensik

ATT&CK-Navigator · IoC-Radar · Exploit-Belege
IoC Intelligence
1 Indikatoren · Defanged · STIX 2.1
CVE-2025-29927
CTI Threat Relationship Graph
Akteure · Techniken · Beziehungen
4 Knoten · 3 Relationen
CVE / Incident Threat Actor Software MITRE ATT&CK CWE Weakness IoC
Exploit & Remediation Lifecycle
PoC · Ausnutzung · Patch-Stufen
CVE-2025-29927
Entdeckung & Meldung
Schwachstelle identifiziert & registriert
Sicherheits-Advisory
Offizielle Warnung & CVE-Zuweisung
Exploit / PoC
Öffentlicher Nachweis/Code verfügbar (Exploit-DB/EUVD)
In-the-Wild Ausnutzung
Aktive Angriffe beobachtet (CISA KEV / EPSS)
Patch & Schutzmaßnahmen
Upstream-Patch-Referenz vorhanden (Commit-/Advisory-Link)
Exploit Weaponization & PoC Radar
Nur belegte Faktoren · kein Score-Theater
CRITICAL WEAPONIZED · Index 100/100
Exploit-DB
EDB-52124
Interaktion
0-Click
Authentifizierung
Nicht erforderlich

Compliance, SLA & Vendor Adherence

Advisory-Prüfung · Score-Einordnung · Fristen
CVSS 9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Impact: 5.18 | Exploitability: 3.89
AVN
Netzwerk (Remote)
Aus der Ferne über das Internet ohne Vorbedingungen exploitbar.
ACL
Niedrig (Low)
Wiederholbar und deterministisch ohne spezielle Race Conditions ausnutzbar.
PRN
Keine (Unauthenticated)
Vollständig unauthentifiziert ohne Benutzerkonto exploitbar.
UIN
Keine (Zero-Click)
Autonom ohne menschliches Zutun ausführbar (Zero-Click Exploitation).
SU
Unverändert (Scope Unchanged)
Auswirkungen verbleiben isoliert in der angreifbaren Anwendungskomponente.
CH
Hoch (Totaler Abfluss)
Vollständiger Zugriff auf alle sensiblen Datenbank- und Speicherinhalte.
IH
Hoch (Volle Manipulation)
Vollständige Modifikation von Dateien, Parametern oder Ausführung von Code.
AN
Keine
Teilweise oder keine Beeinträchtigung.
CISA-SSVC-Triage (vulnrichment)CVE-2025-29927
Exploitation: none (Keine bekannte Ausnutzung)Automatable: yes (Automatisierbar)Technical Impact: total (Vollständig)
Quelle: CISA-ADP vulnrichment · Stand 2025-04-08T15:16:38.515188Z · CISA Coordinator
Advisory Radar

Hersteller-Sicherheitsmeldungen & Patch-Status

In herstellerseitiger Prüfung
Handlungsempfehlung für Administratoren

Hersteller-Advisory noch nicht formal hinterlegt. Regelmäßiges Re-Scanning der CTI-Quellen anberaumt.

Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten CVE-2025-29927: How a Header Bypass in Next.js Broke Auth for Some AI Apps

Thematisch verwandte Begriffe: CVE202529927, Header, Bypass, Nextjs · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag