| Description | This article explains how to apply the new IPS Signature for CVE-2025-29927. |
| Scope | FortiOS. |
| Solution
|
A new vulnerability, CVE-2025-29927 (Next.js Middleware Bypass Vulnerability), has been publicly disclosed. Fortinet products are not affected by this vulnerability. However, it is important to ensure that internal systems are protected from potential exploitation.
To help with this, Fortinet has released a new IPS signature:
This signature is designed to detect and block attempts to exploit this vulnerability, protecting devices within the network.
Action: Set the action to 'Block' to ensure protection is enforced. Make sure the IPS profile is applied to relevant policies so the signature takes effect.
Related document: Intrusion Prevention Vercel.Next.js.x-middleware-subrequest.Authentication.Bypass |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.