ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)
A Server-Side Request Forgery vulnerability in Next.js Middleware affected versions before v14.2.32 and v15.4.7. Misconfigured NextResponse.next calls could let attackers redirect internal requests. A patch on August 25, 2025 fixed the issue for Vercel customers. Self-hosted deployments remain exploitable if not upgraded.
Tap to vote and see what everyone thinks.
Summary by ByteBrief