Using Pich
Pick an advisory
Choose a supported advisory or paste your own advisory text.
Step 1 on the page offers three choices.
| Choice | What happens |
|---|---|
CVE-2025-29927 | Authorization bypass in Next.js middleware. The full advisory text is sent to SERV. |
CVE-2026-64642 | Middleware / proxy bypass in App Router apps built with Turbopack and a single locale. |
| Paste your own | Any Next.js advisory text, between 40 and 12,000 characters. |
Open Read the advisory text SERV will receive to see exactly what is sent. Nothing else from the page goes into the compile request.
Limitation
A pasted advisory can only be checked against the 8 conditions Pich knows how to observe. Anything else becomes a “not checkable from files” item, which pushes affected apps to Needs manual review. See Predicates.