
2025幎3æ21æ¥ãVercelãæäŸããNext.jsãã¬ãŒã ã¯ãŒã¯ã«ãããŠãèªèšŒãã€ãã¹è匱æ§ãCVE-2025-29927ããå ¬éãããŸãããä»åã®èšäºã§ã¯ã Next.js Middlewareã®èªèšŒãã€ãã¹èåŒ±æ§ ãCVE-2025-29927ãã®è åšãšåœ±é¿ãåããé²åºããã€ã³ã¹ã¿ã³ã¹ã®åæããããŠã»ãã¥ãªãã£å¯Ÿçã«ã€ããŠè§£èª¬ããŸãã
Next.js Middlewareã®èªèšŒãã€ãã¹èåŒ±æ§ ãCVE-2025-29927ãã®æŠèŠ
ãã®è匱æ§ã¯ãNext.jsã®MiddlewareãHTTPãªã¯ãšã¹ãåŠçã®ããã»ã¹ã§èªèšŒç¶æ
ãé©åã«ç¢ºèªã§ããªãããšã«èµ·å ããŠãããæªèªèšŒã®ãŠãŒã¶ãŒãæ¬æ¥ã¢ã¯ã»ã¹ã§ããªãä¿è·ããããªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããŠããŸããšããé倧ãªã»ãã¥ãªãã£æ¬ é¥ã§ãã
Vercelã®å
¬åŒçºè¡šã«ãããšãæ¬è匱æ§ã¯Next.jsã®beforeFilesã«ãŒãã£ã³ã°åŠçããžãã¯ã«é¢é£ããŠãããv14.1.0-canary.35以äžã®ããŒãžã§ã³ã§ä¿®æ£ãããŸããã
- èåŒ±æ§ IDïŒCVE-2025-29927
- å ¬éæ¥ïŒ2025幎3æ27æ¥
- 圱é¿ãåããããŒãžã§ã³ïŒNext.js 14.2.25æªæº
- å ¬åŒä¿®æ£çïŒNext.js 12.3.5ã13.5.9ã14.2.25ã15.2.3ããŒãžã§ã³ã§ä¿®æ£
- æ·±å»åºŠïŒCVSSïŒïŒHigh
Criminal IPãæŽ»çšãã Next.js MiddlewareèªèšŒãã€ãã¹èåŒ±æ§ ã®è åšãã³ãã£ã³ã°çµæ
è åšã€ã³ããªãžã§ã³ã¹æ€çŽ¢ãšã³ãžã³ã§ãããCriminal IPãã§ãâX Powered By: Next.jsâãã®ã¯ãšãªãæ€çŽ¢ããããšã§ãå šäžçã«å ¬éãããŠããNext.jsã€ã³ã¹ã¿ã³ã¹ãæ€åºããããšãã§ããŸãã
Criminal IPã®æ€çŽ¢ã¯ãšãªïŒâX Powered By: Next.jsâ

Criminal IPã§ãâX Powered By: Next.jsâãHTTPããããŒãå«ãè³ç£ãæ€åºããçµæãåèš528,421ä»¶ã確èªãããŸããããã®ãã¡ããã§ã«è匱ãªç¶æ ã§è€æ°ã®CVEã«åœ±é¿ãåããŠããè³ç£ã倿°å«ãŸããŠããŸããã
Next.jsè³ç£ã®è©³çްåæãšè匱æ§
ç¹ã«ã以äžã®ããã«ãç¹å®IPã¢ãã¬ã¹ã®ã¬ããŒãããŒãžã§ã¯ãåœIPã¢ãã¬ã¹ã®ãªãŒãã³ããŒãæ å ±ããæ¢ç¥ã®è匱æ§ã®æç¡ããšã¯ã¹ããã€ãDBã®ç¶æ³ãªã©ã確èªããããšãã§ããŸãã

åœIPã¢ãã¬ã¹ã¯ãNext.js Middlewareã®è匱æ§ã®åœ±é¿ãåããå¯èœæ§ã®ããè³ç£ã®äžã€ã§ãããããŒã80ããã³443ãéæŸãããŠããŠã4ä»¶ã®è匱æ§ã®ãã¡ã1ä»¶ã®ãšã¯ã¹ããã€ãDBãæ€ç¥ãããŸããã

<Criminal IPã®è åšãã³ãã£ã³ã°ã«ããæ€åºããããNext.jsã®è匱æ§ã®è åšã«ãããããŠããIPã¢ãã¬ã¹ã®ã¬ããŒã>
åœè©²ãµãŒããŒã«ãã§ã«ååšããæ¢ç¥ã®è匱æ§ã®äžã€ã«ãCVE-2023-44487ãå«ãŸããŠããŸãããã®è匱æ§ã¯HTTP/2 Rapid Resetã®è匱æ§ã§ãããæ»æè
ãçæéã§å€§éã®ã¹ããªãŒã ãçæã»ãªã»ããããããšã§ããµãŒããŒã®ãªãœãŒã¹ãéå°ã«æ¶è²»ãããDDoSæ»æãåŒãèµ·ããå¯èœæ§ã®ããé倧ãªåé¡ã§ãã
CloudflareãGoogleãAWSãªã©ã®äž»èŠãªã¯ã©ãŠããããã€ããŒãããã®è匱æ§ãæªçšããå€§èŠæš¡ãªå®éã®æ»æäºäŸãå ±åããããšããããŸãã
ããã«ããã®è匱æ§ã«ã¯ãã§ã«GitHubäžã§PoCïŒæŠå¿µå®èšŒã³ãŒãïŒãå ¬éãããŠãããã»ãã¥ãªãã£ããããæªé©çšã®ãµãŒããŒã¯ãçŸå®çãªæªçšãªã¹ã¯ã«ãããããããç¶æ ã§ããã€ãŸããããããé²åºããè³ç£ã®è匱æ§ã¯åãªãæœåšçãªã¹ã¯ã§ã¯ãªããå®éã®æ»æã«å©çšããããªã¹ã¯ã極ããŠé«ãããšãæå³ããŸã
ãã®ããã«ãCriminal IPã¯äžçäžã®å€§èŠæš¡ãªWebè³ç£ã®ç¶æ ããªã¢ã«ã¿ã€ã ã§æ€åºããããããŒã«åºã¥ããŠææ¡ã§ããæ»æã«ãããŠãäºåé²åŸ¡ããã³å¯Ÿå¿æŠç¥ã®çå®ã«æŽ»çšãããŸãã
FAQïŒãããã質åïŒ
Q1.ãNext.jsãšã¯ïŒ
Next.jsã¯ãReactããŒã¹ã®Webãã¬ãŒã ã¯ãŒã¯ã§ãããSSRïŒãµãŒããŒãµã€ãã¬ã³ããªã³ã°ïŒãAPIã«ãŒããç»åã®æé©åãªã©ãããŸããŸãªæ©èœãæäŸããŸãããã®ãããããã³ããšã³ããšã³ãžãã¢ã®éã§åºãå©çšãããŠããŸãã
Q2.ããCVE-2025-29927ãã«ã¯ã©ã®ãããªåé¡ããããŸããïŒ
Next.js MiddlewareãèªèšŒç¶æ ãæ£ãã確èªããããªã¯ãšã¹ããèš±å¯ããŠããŸãåé¡ã«èµ·å ããŸãããã®çµæãæ¬æ¥ã¯èªèšŒãå¿ èŠãªããŒãžãAPIãšã³ããã€ã³ãã«ãæªèªèšŒã®ãŸãŸã¢ã¯ã»ã¹ã§ããŠããŸãåé¡ãçããŸãã
Q3.ãã©ã®ããã«å¯Ÿå¿ããã°ããã§ããïŒ
Vercelã¯ããã®è匱æ§ãä¿®æ£ãããããŒãžã§ã³ã§ãã12.3.5ã13.5.9ã14.2.25ã15.2.3ã«ã¢ããããŒãããããšãå§åããŠããã圱é¿ãåããããŒãžã§ã³ã¯çŽã¡ã«ãããã®é©çšãå¿ èŠã§ãã
Q4.ãã©ã®ãããªæ¹æ³ã§é²åºããè³ç£ã確èªã§ããŸããïŒ
ShodanãCriminal IPã®ãããªè åšã€ã³ããªãžã§ã³ã¹ãã©ãããã©ãŒã ã§HTTPããããŒãâX Powered By: Next.jsâããå«ãWebè³ç£ãæ€çŽ¢ããããšã§ãè匱æ§ã®åœ±é¿ãåããããã·ã¹ãã ãç¹å®ããããšãã§ããŸãã
çµè«
Next.jsã¯ãæ°åäžã®ãŠã§ããµãŒãã¹ã§äœ¿çšããã人æ°ãã¬ãŒã ã¯ãŒã¯ã§ãããããä»å玹ä»ããCVE-2025-29927ã¯äžççã«åºç¯å²ã«åœ±é¿ãåãŒãå¯èœæ§ããããŸããå®éãCriminal IPã§æ°åäžä»¶ã®é²åºãããµãŒãã¹ã確èªããããããè匱æ§ãžã®å¯Ÿå¿ã¯å å¶çã«è¡ãããå¿ èŠããããŸãã
Next.jsããŒã¹ã®ã·ã¹ãã ãéçšãããã¹ãŠã®çµç¹ã¯ãéããã«ãããã®é©çšãšã»ãã¥ãªãã£èšºæã宿œããããšãåŒ·ãæšå¥šãããŸããCriminal IPãæŽ»çšããè³ç£ã®èå¥ãšãªã¢ã«ã¿ã€ã æ€åºã¯ãæ»æè ã®ã¢ã¯ã»ã¹ã«å ãããŠè åšã«å¯Ÿå¿ã§ããéèŠãªæŠç¥ãšãªããŸãã
é¢é£ããŠAMI MegaRAC BMCã®è匱æ§åæãšCriminal IPã«ããæ€åºæŠç¥ããåç §ãã ããã
ããŒã¿æäŸïŒCriminal IPïŒhttps://www.criminalip.io/jaïŒãBleepingComputerïŒCritical flaw in Next.js lets hackers bypass authorizationïŒ
ãåç §ïŒÂ
