
Next.js: The Middleware Bypass Menace
A critical flaw in Next.js allows attackers to bypass middleware authorization checks due to a vulnerability tracked as CVE-2025-29927, with a CVSS score of 9.1.
A collection of things from around the web we're reading and have thoughts on.