RootSys Security Research Blog

Welcome to the RootSys blog — a space dedicated to cutting-edge security research, deep-dive vulnerability analyses, and insights from the forefront of offensive security.

Next.js and the Mutated Middleware

This post details our discovery of CVE-2025-57822, a powerful SSRF in Next.js that allows full control over HTTP methods, headers, and target URLs.

Hello World!

Welcome to the RootSys blog! Stay tuned, more is coming soon.

All Posts