
Challenge 11/36: Trusting the Client - Next.js Middleware Bypass (CVE-2025-29927)
ctfsecurityvulnerabilitynextjsmiddlewareauthenticationbypassauthorizationCVE-2025-29927challenge
Challenge 11/36 · Trusting the Client. Middleware bypass (CVE-2025-29927). Medium · Authorization · 30–45 min. Exploiting CVE-2025-29927 to bypass Next.js middleware-based authentication using the x-middleware-subrequest internal header, accessing a protected internal status page without credentials. Spin up the lab: npx create-oss-store my-ctf-lab. See it on the roadmap: https://koadt.github.io/oss-oopssec-store/roadmap#challenge-11. Walkthrough (spoilers, read it once you are stuck): https://koadt.github.io/oss-oopssec-store/posts/middleware-authorization-bypass-cve-2025-29927. Star OopsSec Store on GitHub: https://github.com/kOaDT/oss-oopssec-store