Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Authorization Bypass in Next.js Middleware (github.com/advisories)
25 points by nilsbunger 9 months ago | hide | past | favorite | 2 comments



Looks like it was possible to include the `x-middleware-subrequest` header in your request, tricking the state machine into thinking you'd passed auth already.

(Don't use the user input itself to encode state!)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: