Reference
Supported advisories
The advisories bundled with Pich and what each one can prove.
| Advisory | Summary | Evidence available |
|---|---|---|
CVE-2025-29927GHSA-f82v-jwr5-mffw | Authorization bypass in Next.js middleware | Static check and a controlled runtime proof |
CVE-2026-64642GHSA-6gpp-xcg3-4w24 | Middleware / proxy bypass in App Router apps using Turbopack and a single locale | Static check only |
| Pasted text | Any Next.js advisory | Static check, limited to the predicate vocabulary |