References https://nvd.nist.gov/vuln/detail/CVE-2025-29927 https://github.com/aydinnyunus/CVE-2025-29927 https://www.offsec.com/blog/cve-2025-29927/ https://projectdiscovery.io/blog/nextjs-middleware-authorization-bypass https://jfrog.com/blog/cve-2025-29927-next-js-authorization-bypass/ https://www.assetnote.io/resources/research/doing-the-due-diligence-analyzing-the-next-js-middleware-bypass-cve-2025-29927 https://securitylabs.datadoghq.com/articles/nextjs-middleware-auth-bypass/ https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/middleware/Next.js-%E4%B8%AD%E9%97%B4%E4%BB%B6%E9%89%B4%E6%9D%83%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9E-CVE-2025-29927.md https://www.cnblogs.com/CVE-Lemon/p/18797265 https://blog.nsfocus.net/cve-2025-29927/ https://avd.aliyun.com/detail?id=AVD-2025-29927 https://zhero-web-sec.github.io/research-and-things/nextjs-and-the-corrupt-middleware
Related VulnerabilitiesPoCCVE-2026-28141: NextGEN Gallery <= 4.2.3 - Reflected Cross-Site ScriptingPoCCVE-2026-29059: Windmill/Nextcloud Flow < 1.603.3 - Unauthenticated Path TraversalWindmill/Nextcloud Flow /api/w/_/jobs_u/get_log_file/ 目录遍历漏洞(CVE-2026-29059)Windmill/Nextcloud Flow /api/w/_/jobs_u/get_log_file/ 路径穿越漏洞PoCNext.js WebSocket 服务器端请求伪造漏洞(CVE-2026-44578)ERPNext /api/method/erpnext.stock.doctype.material_request.material_request.get_material_requests_based_on_supplier SQL 注入漏洞(CVE-2025-52039)ERPNext /api/method/erpnext.stock.doctype.stock_reconciliation.stock_reconciliation.get_stock_balance_for SQL 注入漏洞(CVE-2025-52041)ERPNext /api/method/erpnext.controllers.queries.get_blanket_orders SQL 注入漏洞(CVE-2025-52040)ERPNext /api/method/erpnext.buying.doctype.request_for_quotation.request_for_quotation.get_rfq_containing_supplier SQL 注入漏洞(CVE-2025-52042)ERPNext /api/method/erpnext.stock.utils.get_stock_balance SQL 注入漏洞(CVE-2025-52044)ERPNext /api/method/erpnext.accounts.doctype.chart_of_accounts_importer.chart_of_accounts_importer.import_coa SQL 注入漏洞(CVE-2025-52043)PandoraNext-TokensTool /api/selectSetting;login 权限绕过漏洞(CVE-2024-50641)