漏洞描述
Next.js contains a critical middleware bypass vulnerability affecting versions 11.1.4 through 15.2.2. The vulnerability allows attackers to bypass middleware security controls by sending a specially crafted 'x-middleware-subrequest' header, which can lead to authorization bypass and other security control circumvention.
影响产品
修复建议
Upgrade to Next.js 14.2.25 or 15.2.3 or later. If upgrading is not possible, block the x-middleware-subrequest header at the WAF or server level.
参考链接
zhero-web-sec.github.iohttps://zhero-web-sec.github.io/research-and-things/nextjs-and-the-corrupt-middleware↗github.comhttps://github.com/vercel/next.js/security/advisories/GHSA-f82v-jwr5-mffw↗slcyber.iohttps://slcyber.io/assetnote-security-research-center/doing-the-due-diligence-analysing-the-next-js-middleware-bypass-cve-2025-29927/↗