ended6월 28일· 1 sources
Reading a protected Next.js page with zero credentials (CVE-2025-29927)
Why it matters
Exploiting CVE-2025-29927 to bypass Next.js middleware-based authentication using the x-middleware-subrequest internal header, accessing a protected internal status page without credentials. Next.js u...
1
Sources
+0
24h
—
Growth
4d
Active