CVE-2025-29927: Next.js Flaw Let Attackers Bypass Auth, Hit 59,000 Servers
A security campaign dubbed Operation PCPcat exploited a critical vulnerability in the Next.js framework in early December 2025, compromising over 59,000 servers within 48 hours. The flaw, tracked as CVE-2025-29927, allowed attackers to bypass middleware-based authentication entirely by sending a spoofed internal header called x-middleware-subrequest. Because Next.js trusted this header without verifying its origin, attackers could skip all auth checks and access protected admin routes unchallenged. The breach resulted in an estimated 300,000 to 590,000 stolen credential sets, including SSH keys and cloud tokens, with a success rate exceeding 64 percent. Patched versions have since been released, and security experts advise developers to enforce authorization checks directly within route handlers rather than relying solely on middleware.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in