
CVE-2026-105238: NextChat's proxy trusts the x-base-url header, so anyone can make the server send requests. Exploit is public, no fix merged yet. Details: https://vulntracker.io/cves/CVE-2026-105238 #NextChat #SSRF #CVE #InfoSec https://t.co/gWj0xwROv0


