Next.js and the Mutated Middleware
This post details our discovery of CVE-2025-57822, a powerful SSRF in Next.js that allows full control over HTTP methods, headers, and target URLs.
This post details our discovery of CVE-2025-57822, a powerful SSRF in Next.js that allows full control over HTTP methods, headers, and target URLs.
Welcome to the RootSys blog! Stay tuned, more is coming soon.