All verified exploits

CVE-2025-29927 Middleware Authorization Bypass

Deterministic critical Next.js Added cve-verified-cve-2025-29927

Sends a crafted header that causes Next.js to skip all middleware, completely bypassing authentication and authorization on protected routes.

Is your app exploitable through CVE-2025-29927?

Scan your domain free