¡¾Îó²îͨ¸æ¡¿Next.js ÖÐÐļþÊÚÈ¨ÈÆ¹ýÎó²î(CVE-2025-29927)

Ðû²¼Ê±¼ä 2025-03-24

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Next.js ÖÐÐļþÊÚÈ¨ÈÆ¹ýÎó²î

CVE   ID

CVE-2025-29927

Îó²îÀàÐÍ

ÊÚÈ¨ÈÆ¹ýÎó²î

·¢Ã÷ʱ¼ä

2025-03-24

Îó²îÆÀ·Ö

9.1

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


Next.jsÊÇÒ»¸ö»ùÓÚReactµÄ¿ªÔ´¿ò¼Ü£¬£¬ £¬ÓÃÓÚ¹¹½¨ÏÖ´úwebÓ¦ÓóÌÐò¡£ ¡£¡£ËüÌṩÁËЧÀÍÆ÷¶ËäÖȾ£¨SSR£©¡¢¾²Ì¬ÌìÉú£¨SSG£©¡¢API·Óɵȹ¦Ð§£¬£¬ £¬Ö§³Ö¿ìËÙ¹¹½¨¸ßÐÔÄܵÄȫջӦÓᣠ¡£¡£Next.jsÌṩÁË¿ª·¢ºÍÉú²úÇéÐεÄÓÅ»¯£¬£¬ £¬Ò×ÓÚ°²ÅÅ£¬£¬ £¬ÆÕ±éÓ¦ÓÃÓÚÆóÒµ¼¶Ó¦ÓúÍÄÚÈÝÇý¶¯µÄÍøÕ¾¡£ ¡£¡£


2025Äê3ÔÂ24ÈÕ£¬£¬ £¬918²©ÌìÌü¯ÍÅVSRC¼à²âµ½ÍâÑóÇå¾²Ñо¿Ô±ÔÚzhero-web-secÐû²¼µÄÎÄÕÂÖÐÖ¸³ö£¬£¬ £¬Next.js 14.2.25¼°15.2.3֮ǰµÄ°æ±¾±£´æÒ»¸öÑÏÖØµÄÖÐÐļþÊÚÈ¨ÈÆ¹ýÎó²î¡£ ¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÔÚÇëÇóÖÐÌí¼Óx-middleware-subrequestÍ·²¿£¬£¬ £¬ÈƹýÖÐÐļþµÄÊÚȨºÍÈÏÖ¤¼ì²é£¬£¬ £¬½ø¶ø»á¼ûÊܱ£»£»£»¤µÄ×ÊÔ´»òÈÆ¹ýÇå¾²¿ØÖÆ¡£ ¡£¡£¸ÃÎó²î¿ÉÄܵ¼ÖÂÐÅϢй¶¡¢¶ñÒâÊý¾Ý»á¼ûµÈÇ徲Σº¦¡£ ¡£¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ9.1£¬£¬ £¬Îó²î¼¶±ðÑÏÖØ¡£ ¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


11.1.4 <= next.js <= 13.5.6
14.0 <= next.js < 14.2.25
15.0 <= next.js<15.2.3


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


¹Ù·½ÒÑÐû²¼ÐÞ¸´°æ±¾£¬£¬ £¬½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ì¸üС£ ¡£¡£


ÏÂÔØÁ´½Ó£ºhttps://github.com/vercel/next.js/releases/


3.2 ÔÝʱ²½·¥


ÈôÊÇÎÞ·¨Á¬Ã¦Éý¼¶£¬£¬ £¬½¨Òéͨ¹ý×èÖ¹°üÀ¨x-middleware-subrequestÍ·²¿µÄÍⲿÇëÇóÀ´ïÔ̭Σº¦¡£ ¡£¡£Õâ¿ÉÒÔͨ¹ýÉèÖÃWebЧÀÍÆ÷»òʹÓ÷À»ðǽ¹æÔòÀ´ÊµÏÖ¡£ ¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬ £¬ïÔ̭ϵͳÎó²î£¬£¬ £¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£ ¡£¡£
? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬ £¬Ð޸ķÀ»ðǽսÂÔ£¬£¬ £¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬ £¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬ £¬ïÔÌ­¹¥»÷Ãæ¡£ ¡£¡£
? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬ £¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£ ¡£¡£
? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬ £¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬ £¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£ ¡£¡£
? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£ ¡£¡£


3.4 ²Î¿¼Á´½Ó


https://github.com/vercel/next.js/security/advisories/GHSA-f82v-jwr5-mffw
https://github.com/vercel/next.js/commit/52a078da3884efe6501613c7834a3d02a91676d2
https://github.com/vercel/next.js/commit/5fd3ae8f8542677c6294f32d18022731eab6fe48
https://zhero-web-sec.github.io/research-and-things/nextjs-and-the-corrupt-middleware
https://nvd.nist.gov/vuln/detail/CVE-2025-29927