Hacker News with Generative AI: Middleware

CVE-2025-46336 (rack-session): Rack session gets restored after deletion (rubysec.com)
When using the Rack::Session::Pool middleware, simultaneous rack requests can restore a deleted rack session, which allows the unauthenticated user to occupy that session.
Authorization Bypass in Next.js Middleware (github.com/advisories)
It is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware.
Red Hat's Java middleware development team to be transferred to IBM (redhat.com)
Today, we’re sharing that Red Hat and IBM will join forces to secure the future of the Java application ecosystem for our customers.
ECAL – Enhanced Communication Abstraction Layer / Pub-Sub Middleware (github.com/eclipse-ecal)
The enhanced Communication Abstraction Layer (eCAL) is a middleware that enables scalable, high performance interprocess communication on a single computer node or between different nodes in a computer network.