CVE-2026-44572PoC(vercel / next.js)

LOWCVSS 5.9 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for vercel next.js systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-nextjs-data header on a normal request to a path handled by middleware that returns a redirect. When that happened, the middleware/proxy could treat the request as a data request and replace the standard Location redirect header with the internal x-nextjs-redirect header. Browsers do not follow x-nextjs-redirect, so the response became an unusable redirect for normal clients. If the application was deployed behind a CDN or reverse proxy that caches 3xx responses without varying on this header, a single attacker request could poison the cached redirect response for the affected path. Subsequent visitors could then receive a cached redirect response without a Location header, causing a denial of service for that redirect path until the cache entry expired or was purged. This vulnerability is fixed in 15.5.16 and 16.2.5.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-349

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • next.js

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 5 signals
  • Peaked 1d ago at 2 mentions (2026-05-10); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
next.js

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-05-08: 1Mentions · 2026-05-09: 1Mentions · 2026-05-10: 2Mentions · 2026-05-11: 1PoC Mentioned / Linked · 2026-05-08: 1PoC Mentioned / Linked · 2026-05-09: 1PoC Mentioned / Linked · 2026-05-10: 2PoC Mentioned / Linked · 2026-05-11: 1Exploit Tool / Code · 2026-05-08: 1Exploit Tool / Code · 2026-05-10: 2Exploit Tool / Code · 2026-05-11: 105-0805-0905-1005-11
Signal classification1 categories
PoC
5100.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-05-081
PoC1
2026-05-091
PoC1
2026-05-102
PoC2
2026-05-111
PoC1
Full discourse5 posts
  • dw1@dwisiswant0
    PoC

    CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572 https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    The text lists multiple CVE identifiers and links to a GitHub repository hosting PoC (proof‑of‑concept) code for those vulnerabilities.

    4126765045576.6K
    16.0K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    The tweet announces a GitHub repository containing Proof of Concept code for a range of Next.js v16.2.4 CVEs, but does not mention active exploitation, patches, or technical details.

    144220813713.7K
    158.6K followersView on X
  • Psycho 🎭@Psycho10k_
    PoC

    Next.js v16.2.4 Security PoC Collection CVE-2026-23870 CVE-2026-44575 CVE-2026-44579 CVE-2026-44574 CVE-2026-44578 CVE-2026-44573 CVE-2026-44581 CVE-2026-44580 CVE-2026-44577 CVE-2026-44576 CVE-2026-44582 CVE-2026-44572 https://github.com/dwisiswant0/next-16.2.4-pocs via: Pr0xy

    Post summary

    The post announces a GitHub collection of Proof‑of‑Concept exploits for various CVEs affecting Next.js v16.2.4, with no indication of active exploitation or available patches.

    08043302.5K
    455 followersView on X
  • termireum@termireum
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    A GitHub repository containing proof‑of‑concept code for multiple CVEs affecting Next.js v16.2.4, without evidence of active exploitation or detailed technical info.

    0101810684
    758 followersView on X
  • Huda Al-Assaf@0x0Huda
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    A GitHub repository containing Proof‑of‑Concept code for several Next.js v16.2.4 CVEs is shared, with no indication of active exploitation, patches, or technical details.

    020543.0K
    727 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvercelnext.js-node.js-

Explore more