A Next.js middleware authorization bypass (CVE-2025-29927): forging the internal x-middleware-subrequest header skips the auth check on /admin and leaks a recovery key.
© 2026 Zw4rts. All rights reserved.