It looks like not many people are discussing this yet, but I just received an email from Replit a few hours ago containing a security report regarding several versions of Next.js.
This enables anyone to effortlessly access middleware-protected routes by simply modifying a header in an HTTP request. So, seize the opportunity!
Just kidding. I had to update urgently just in case. Even though Vercel says deployments with Vercel, Netlify or Cloudflare are not affected.
This seems like a huge deal.