CVE-2025-29927 | vercel Next.js up to 14.2.24/15.2.2 Header x-middleware-subrequest improper authorization (GHSA-f82v-jwr5-mffw)
A vulnerability was found in vercel Next.js up to 14.2.24/15.2.2 and classified as critical. Affected by this issue is some unknown functionality of the component Header Handler. The manipulation of the argument x-middleware-subrequest leads to improper authorization.
This vulnerability is handled as CVE-2025-29927. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.