
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Lame Brown Dev</title>
      <link>https://lamebrown.dev/blog</link>
      <description>He warned us not to confuse popularity with correctness. I listened. I admired. And then I shipped a React app anyway. This site is my quiet apology -&gt; typed, not typeset | A tribute to Knuth</description>
      <language>en-us</language>
      <managingEditor>salman@felic.io (Salman)</managingEditor>
      <webMaster>salman@felic.io (Salman)</webMaster>
      <lastBuildDate>Fri, 14 Mar 2025 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://lamebrown.dev/tags/security/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://lamebrown.dev/blog/cve-2025-29927-nextjs-middleware-auth</guid>
    <title>Why Middleware-Only Auth in Next.js Is Still Dangerous (Lessons From the CVE-2025-29927 Bypass)</title>
    <link>https://lamebrown.dev/blog/cve-2025-29927-nextjs-middleware-auth</link>
    <description>CVE-2025-29927 let attackers bypass Next.js middleware with a single header. If your auth lives only in middleware you were wide open. Here is what happened and how to fix it properly.</description>
    <pubDate>Fri, 14 Mar 2025 00:00:00 GMT</pubDate>
    <author>salman@felic.io (Salman)</author>
    <category>next.js</category><category>security</category>
  </item>

    </channel>
  </rss>
