Doing the Due Diligence: Analyzing the Next.js Middleware Bypass (CVE-2025-29927)
Introduction
Over the last few days, there has been deep unrest in the Next.js ecosystem due to a critical CVE released on the 21st of March (CVE-2025-29927) that allows attackers to potentially bypass authentication mechanisms that are implemented at the middleware layer.
Since the release of the CVE, our security r...