Next.js rocked by critical 9.1 level exploit...

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A critical 9.1 security exploit affecting Next.js allows attackers to bypass authentication and authorization in middleware, putting many applications at risk. The vulnerability was discovered and reported on February 27th but was only patched on March 18th, leading to significant controversy and competitive drama between companies like Cloudflare and Vercel. Developers are advised to upgrade their Next.js apps immediately, especially if using middleware for security purposes, to mitigate potential damage.

3m watch time
1 Comment

Sort: