Sends a crafted header that causes Next.js to skip all middleware, completely bypassing authentication and authorization on protected routes.
Is your app exploitable through CVE-2025-29927?