[FALSE-POSITIVE] ...CVE-2025-29927

Author: dl1richCreated Sep 9, 2026Updated Sep 9, 2026
Labelsfalse-positivewaiting for more info

Template IDs or paths

markdown
-CVE-2025-29927

False positive. 

[CVE-2025-29927] Next.js Middleware Bypass (@pdresearch,@pdteam,@hazedic) [critical]

It only checks a few headers then wrongly verifies the vulnerability (after remediation) 

It would be a similar fix to https://github.com/projectdiscovery/nuclei-templates/issues/17019

Which was closed around 5 hours ago (exact same issue) also do we need two templates for the same vuln? 

I can confirm the target in this case was remediated I proved via manual testing. But yes this is a false positive now.

Environment

markdown
- OS: Windows
- Nuclei: Latest
- Go: Latest

Steps To Reproduce

nuclei -l hosts.txt -id CVE-2025-29927 -vv

hosts.txt would contain the affected target

Relevant dumped responses

bash

Anything else?

No response

Source: projectdiscovery/nuclei-templates