CVE-2025-29972 is a critical server-side request forgery (SSRF) vulnerability in Microsoft Azure Storage Resource Provider (SRP), an exclusively hosted Azure service. According to the provided content, the flaw allows an authorized attacker to perform spoofing over a network. Microsoft classifies the issue as CWE-918 and scores it CVSS v3.1 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H), indicating network-reachable exploitation with low attack complexity, low privileges required, no user interaction, changed scope, and high impact across confidentiality, integrity, and availability. Specific vulnerable functions or request-processing paths were not provided in the source material.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept exploit for CVE-2025-29927, a critical vulnerability in Next.js (versions prior to 14.2.25 and 15.2.3) that allows attackers to bypass middleware-based authentication and authorization by injecting a crafted 'x-middleware-subrequest' HTTP header. The main exploit script, 'exploit.py', is a Python tool that allows users to specify a target hostname, port, HTTP method, and path (defaulting to '/protected'). It sends two requests: one normal and one with the malicious header, and checks if protected content can be accessed without proper authentication. The script saves successful responses to 'vuln_middleware.html' for further inspection. The repository is structured with a README (explaining the vulnerability and usage), a license, the exploit script, and a requirements file (listing 'colorama' as a dependency). The exploit is network-based and targets web applications running vulnerable Next.js versions, demonstrating unauthorized access to protected resources.
This repository provides a proof-of-concept exploit for CVE-2025-29927, a critical vulnerability in Next.js (versions prior to 14.2.25 and 15.2.3) that allows attackers to bypass middleware-based authentication and authorization. The main exploit script, 'exploit.py', is a Python tool that sends HTTP requests to a specified target and path, optionally injecting the 'x-middleware-subrequest' header with a value of 'middleware'. This header manipulation exploits the vulnerability, potentially granting unauthorized access to protected resources (such as admin pages or user dashboards) if the target is running a vulnerable Next.js version. The script compares normal and exploit requests, checks for the presence of protected content in the response, and saves successful responses to a local HTML file for analysis. The repository is structured with a single exploit script, a README with usage instructions and vulnerability details, a requirements file for dependencies (colorama), and a license. No hardcoded endpoints are present; the user specifies the target hostname, port, and path. The exploit is network-based and demonstrates the vulnerability's impact but does not provide weaponized or post-exploitation features.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical spoofing vulnerability in Azure Storage Resource Provider with a CVSS base score of 9.9. The content states it had already been addressed by Microsoft prior to the release.
Azure Storage Resource Provider spoofing vulnerability fixed by Microsoft in production.
A vulnerability in Azure Storage Resource Provider.
A spoofing vulnerability in Azure Storage Resource Provider.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.