I break down a CVE where an attacker could bypass middleware in every Next.js version. What was it trying to do? How did it break? Why do we use middleware at all?
Next.js middleware was completely optional…
I break down a CVE where an attacker could bypass middleware in every Next.js version. What was it trying to do? How did it break? Why do we use middleware at all?