With #CVE_2025_29927, Next.js has now suffered its second major vulnerability in just three months, following #CVE_2024_51479.

I originally built CVE Crowd with #NextJS.

However, as the application became more complex (especially with authentication), I decided to switch to a framework I was more familiar with.

Honestly, I’m feeling a bit relieved about that right now...

#Pentesting #AppSec #InfoSec #CyberSecurity #BugBounty #Hacking #CVE #CVECrowd

CVE Alert: CVE-2024-51479 - RedPacket Security

Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in middleware

RedPacket Security