Skip to content

Add rule for CVE-2025-29927: Authorization Bypass in Next.js Middleware #4051

@oscarhermoso

Description

@oscarhermoso

Motivation

Authorization Bypass in Next.js Middleware

GHSA-f82v-jwr5-mffw

Proposed solution

Add rule to detect requests containing header x-middleware-subrequest

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions