Postmortem on Next.js Middleware bypass - Vercel
Last week, we published CVE-2025-29927 and patched a critical severity vulnerability in Next.js. Here’s our post-incident analysis and next steps.