
the research paper is out: Next.js and the corrupt middleware: the authorizing artifact result of a collaboration with @inzo____ that led to CVE-2025-29927 (9.1-critical) zhero-web-sec.github.io/research-and-t… enjoy the read!
inzo
212 posts


the research paper is out: Next.js and the corrupt middleware: the authorizing artifact result of a collaboration with @inzo____ that led to CVE-2025-29927 (9.1-critical) zhero-web-sec.github.io/research-and-t… enjoy the read!

I’ve received several similar offers over the past few months from companies of various sizes involving conducting research + writing of the related papers, which generally included: - transferring research intellectual property - per-research payment, sometimes with a fixed fee




honored to see two of my research works selected for the initial nominations they’ve been the most fruitful for me in practice, with ongoing discoveries of vuln assets, incl. several major platforms, and six figures in rewards If they helped you in any way, consider voting-14/01

grateful;


release of our new paper (w/ @inzo____) which resulted in CVE-2025-64525: Astro framework and standards weaponization from path-based middleware protection bypass to potential SSRF & XSS + full bypass of CVE-2025-61925 on @astrodotbuild zhero-web-sec.github.io/research-and-t…

@e11iptic spent more time writing than reading this week : zhero-web-sec.github.io/research-and-t…



The whitepaper is live! Learn how to win the HTTP desync endgame... and why HTTP/1.1 needs to die: http1mustdie.com

back to work with @zhero___ and a new vulnerability on @nextjs that led to CVE-2025-49826 both routers are impacted: app router: framework's cache is directly impacted on ISR pages, regardless of the presence of a CDN pages router: SSR pages only + requires a misconfigured CDN

