shipfeedAI news, curated daily

00:38:22 CET
21 MAY00:38:22shipfeed
pull to refreshlast sync
Just in — 30 new
§ feed · storyline

Protection against Next.js CVE-2025-29927

Vercel confirms its customers are unaffected by Next.js CVE-2025-29927, a middleware auth-bypass vulnerability, while urging all users to update to patched versions.

Mar 22 · · primary fetch1 sourceupdated Mar 22 ·

A security vulnerability in Next.js was , which allows malicious actors to bypass authorization in Middleware when targeting the header.responsibly disclosedx-middleware-subrequest .

We still recommend updating to the patched versions. Learn more about .Vercel customers are not affectedCVE-2025-29927 Read more

read full article on vercel.com
§ sources1 publication · timeline below
  1. vercel.comProtection against Next.js CVE-2025-29927primary