Featured resource
2026 Tech Forecast
2026 Tech Forecast

Stay ahead of what’s next in tech with predictions from 1,500+ business leaders, insiders, and Pluralsight Authors.

Get these insights
  • Course

Authentication Bypass Vulnerability in Next.js CVE-2025-29927: What You Should Know

Discover the key information you need to know about CVE-2025-29927, an authentication bypass vulnerability in the middleware layer in Vercel’s Next.js.

Beginner
11m
(0)

Created by Michael Teske and Matthew Lloyd Davies

Last Updated Apr 02, 2025

Course Thumbnail
  • Course

Authentication Bypass Vulnerability in Next.js CVE-2025-29927: What You Should Know

Discover the key information you need to know about CVE-2025-29927, an authentication bypass vulnerability in the middleware layer in Vercel’s Next.js.

Beginner
11m
(0)

Created by Michael Teske and Matthew Lloyd Davies

Last Updated Apr 02, 2025

Get started today

Access this course and other top-rated tech content with one of our business plans.

Try this course for free

Access this course and other top-rated tech content with one of our individual plans.

This course is included in the libraries shown below:

  • Security
What you'll learn

CVE-2025-29927 is an authentication bypass vulnerability in the middleware layer in Vercel’s Next.js. Exploitation is trivial and can be achieved by adding an x-middleware-subrequest header with a specially crafted value in the request. The Next.js middleware will incorrectly process the header and bypass the authentication check. This course will give you a clear understanding of this vulnerability, its potential impact, and the urgency of applying the newly released patches. We will walk through the security implications for affected systems, explore risk mitigation strategies, and provide actionable steps to safeguard your organization against exploitation.

Authentication Bypass Vulnerability in Next.js CVE-2025-29927: What You Should Know
Beginner
11m
(0)
Table of contents

About the author
Michael Teske - Pluralsight course - Authentication Bypass Vulnerability in Next.js CVE-2025-29927: What You Should Know
Michael Teske
71 courses 4.5 author rating 888 ratings

Michael Teske is an Author Evangelist with Pluralsight helping people elevate their skills. He has 20+ years of experience in IT Ops, including 17 as an IT instructor at a community college.

About the author
Matthew Lloyd Davies - Pluralsight course - Authentication Bypass Vulnerability in Next.js CVE-2025-29927: What You Should Know
Matthew Lloyd Davies
41 courses 4.7 author rating 47 ratings

Matt has a degree in Chemical engineering and a PhD in mathematical chemistry. He is also a GIAC certified incident handler and penetration tester and has regulated cyber security in the UK civil nuclear sector for many years.

Get started with Pluralsight