Web Hack List

Collected research

Next.js and the corrupt middleware: the authorizing artifact

Finds that a crafted internal middleware header can make vulnerable Next.js deployments skip middleware execution. Because applications commonly implement authorization in middleware, direct requests bearing the header can bypass access controls and reach protected routes.

Record

Researcher
zhero and Yasser Allam
Published by
zhero_web_security
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of zhero and Yasser Allam, first published at the original source. Preserved copies are kept so the citation survives its host.