Mitigate CVE-2025-29927 in Next.js

Strip the x-middleware-subrequest header with a Rules Engine rule on Azion Applications, so a crafted request cannot skip Next.js middleware.

Last updated

View as Markdown Agent setup