Tech

Critical security flaw in Next.js could spell big trouble for JavaScript users

Share
Share


  • Researchers spot critical vulnerability in Next.js
  • If authorizations happen in middleware, they could be bypassed in older versions
  • A patch, and a temporary workaround, are both available, so update now

Experts have warned there is a critical severity flaw in the Next.js open source web development framework which allows threat actors to bypass authorization checks.

Security researcher Rachid.A from Zhero Web Security posted an in-depth analysis of the findings, with the vulnerability tracked as CVE-2025-29927, and receiving a severity score of 9.1/10 (critical).

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Apple expects 0M tariff hit, US iPhone supply shifts to India
Tech

Apple expects $900M tariff hit, US iPhone supply shifts to India

Apple chief Tim Cook says most of the iPhones brought into the...

Japan dating app uses govt data to verify unmarried status
Tech

Japan dating app uses govt data to verify unmarried status

Credit: Pixabay/CC0 Public Domain A popular Japanese dating app has introduced a...

Real-time boundary detection from noisy images and single-shot HDR imaging expand applications
Tech

Real-time boundary detection from noisy images and single-shot HDR imaging expand applications

Credit: Purdue University Patent-pending imaging technologies created in Purdue University’s College of...