Skip to content
Doing the Due Diligence: Analyzing the Next.js Middleware Bypass (CVE-2025-29927) Introduction Over the last few days, there has been deep unrest in the Next.js ecosystem due to a critical CVE released on the 21st of March (CVE-2025-29927) that allows attackers to potentially bypass authentication mechanisms that are implemented at the middleware layer. Since the release of the CVE, our security r...
Doing the Due Diligence: Analyzing the Next.js Middleware Bypass (CVE | Huntaegis