HomeSecurityNCSC urges immediate patching of Next.js vulnerability

NCSC urges immediate patching of Next.js vulnerability

The UK's leading cybersecurity agency has urged users of Next.js, a popular open source web development framework, to immediately patch a critical vulnerability.

See also: NCSC issues Guidelines for Protecting Research and Innovation

Next.js vulnerability

The National Cyber ​​Security Center (NCSC) warned in a post on Friday about an authorization bypass vulnerability found in Next.js, a React-based framework used to develop full-stack web applications worldwide.

An attacker can exploit this vulnerability by sending an external request to the system, which the system will treat as an internal request, bypassing authorization checks and providing unauthorized access to sensitive data, he explained.

“Proof-of-concept for this vulnerability is widely and freely available.”

The CVE-2025-29927 was patched by Next.js administrators on March 22, after a responsible and private report to the team in February.

Next.js uses an internal header x-middleware-subrequest to prevent recursive requests from causing infinite loops, as explained.

See also: NCSC: Artificial intelligence (AI) will increase ransomware attacks

“The security report revealed that it was possible to bypass the execution of the middleware, which could allow requests to bypass critical checks – such as validation of authorization cookies – before reaching the routes.“

NCSC urges immediate patching of Next.js vulnerability

The Next.js framework vulnerability affects all 13.x versions before 13.5.9, all 14.x versions before 14.2.25, all 15.x versions before 15.2.3, and all versions from 11.1.4 up to, but not including, 12.3.5.

The NCSC stated that “if upgrading to a stable version is not feasible, the vendor has suggested blocking external user requests containing the 'x-middleware-subrequest' header from accessing application your Next.js”

The agency also urged organizations to monitor logs for potential attacks.

Rapid7 explained that because the reported CVE affects the Next.js application framework and middleware configurations may vary, so does the potential impact of the vulnerability.

See also: Switzerland: Critical infrastructures must report cyberattacks

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

An open source development framework is a set of pre-built tools, libraries, and components that developers to build web applications. The key aspect of these frameworks is that they are open source, meaning that their source code is freely available for anyone to use, modify, and distribute. These frameworks typically provide a structure or blueprint to streamline the development process, reducing the need to build common features from scratch, and offering best practices and patterns to ensure a more efficient, maintainable, and scalable code base.

Source: infosecurity-magazine

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS