CVEs tagged web, newest first.
1 CVERSS
CVE-2025-29927
A crafted x-middleware-subrequest header lets an attacker skip Next.js middleware execution entirely, bypassing authentication/authorization checks implemented in middleware.