# Protection against Next\.js CVE\-2025\-29927

**Published:** March 22, 2025 | **Authors:** Aaron Brown

---

A security vulnerability in Next.js was [responsibly disclosed](https://github.com/advisories/GHSA-f82v-jwr5-mffw), which allows malicious actors to bypass authorization in Middleware when targeting the `x-middleware-subrequest` header.

**Vercel customers are not affected**. We still recommend updating to the patched versions. Learn more about [CVE-2025-29927](https://nextjs.org/blog/cve-2025-29927).

---

📚 **More updates:** [View all changelog entries](/changelog/sitemap.md) | [Blog](/blog/sitemap.md)