ended6월 28일· 1 sources

Reading a protected Next.js page with zero credentials (CVE-2025-29927)

Why it matters

Exploiting CVE-2025-29927 to bypass Next.js middleware-based authentication using the x-middleware-subrequest internal header, accessing a protected internal status page without credentials. Next.js u...

1
Sources
+0
24h
Growth
4d
Active

Sources

Related Issues