Collected research
Next.js and the corrupt middleware: the authorizing artifact
Finds that a crafted internal middleware header can make vulnerable Next.js deployments skip middleware execution. Because applications commonly implement authorization in middleware, direct requests bearing the header can bypass access controls and reach protected routes.
Record
- Researcher
- zhero and Yasser Allam
- Published by
- zhero_web_security
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of zhero and Yasser Allam, first published at the original source. Preserved copies are kept so the citation survives its host.