CVE-2026-44573PoC(vercel / next.js)

MEDIUMCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch vercel next.js systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-less /_next/data/<buildId>/<page>.json requests. In affected configurations, middleware does not run for the unprefixed data route, allowing an attacker to retrieve SSR JSON for protected pages without passing the intended authorization checks. This vulnerability is fixed in 15.5.16 and 16.2.5.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863CWE-551

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • next.js

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 9 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-05-09); latest day: 1
  • 9 total mentions across 6 days

Affected systems

Vendors
Products
next.js

Deep dive

Activity timeline9 mentions / 6d
01122Mentions · 2026-05-08: 1Mentions · 2026-05-09: 2Mentions · 2026-05-10: 2Mentions · 2026-05-11: 2Mentions · 2026-05-12: 1Mentions · 2026-05-15: 1PoC Mentioned / Linked · 2026-05-08: 1PoC Mentioned / Linked · 2026-05-09: 2PoC Mentioned / Linked · 2026-05-10: 2PoC Mentioned / Linked · 2026-05-11: 1Exploit Tool / Code · 2026-05-08: 1Exploit Tool / Code · 2026-05-09: 2Exploit Tool / Code · 2026-05-10: 2Exploit Tool / Code · 2026-05-11: 1Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-05-15: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-15: 105-0805-0905-1005-1105-1205-15
Signal classification4 categories
PoC
666.7%
Disclosure
111.1%
General
111.1%
Patch
111.1%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-081
PoC1
2026-05-092
PoC2
2026-05-102
PoC2
2026-05-112
Disclosure1PoC1
2026-05-121
General1
2026-05-151
Patch1
Full discourse9 posts
  • dw1@dwisiswant0
    PoC

    CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572 https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    The tweet lists multiple CVEs and links to a GitHub repository containing proof‑of‑concept code, indicating the vulnerabilities have been demonstrated but without mention of active exploitation, patches, or detailed technical attributes.

    4126765045576.6K
    16.0K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    The post shares a GitHub repository containing Proof‑of‑Concept code for multiple Next.js v16.2.4 vulnerabilities, with no indication of active exploitation or available patches.

    144220813713.7K
    158.6K followersView on X
  • Psycho 🎭@Psycho10k_
    PoC

    Next.js v16.2.4 Security PoC Collection CVE-2026-23870 CVE-2026-44575 CVE-2026-44579 CVE-2026-44574 CVE-2026-44578 CVE-2026-44573 CVE-2026-44581 CVE-2026-44580 CVE-2026-44577 CVE-2026-44576 CVE-2026-44582 CVE-2026-44572 https://github.com/dwisiswant0/next-16.2.4-pocs via: Pr0xy

    Post summary

    The post shares a collection of Proof‑of‑Concept codes for multiple CVEs in Next.js v16.2.4, directing readers to a GitHub repository that likely contains exploit scripts.

    08043302.5K
    455 followersView on X
  • termireum@termireum
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    This post shares a GitHub repository containing proof‑of‑concept code for multiple Next.js CVEs, with no indication of active attacks, patches, or remediation details.

    0101810684
    758 followersView on X
  • Huda Al-Assaf@0x0Huda
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    The message announces a GitHub repository of Proof‑of‑Concept code for several CVEs in Next.js v16.2.4, without indicating active exploitation, patches, or technical details.

    020543.0K
    727 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 High - Next.js Multiple Vulnerabilities (CVE-2026-44573, CVE-2026-44574, CVE-2026-44575, CVE-2026-44578, CVE-2026-44579, CVE-2026-45109) Multiple issues were identified in Next.js affecting App Router, Pages Router, Server Components, WebSockets, and caching mechanisms. These include middleware/proxy bypasses, denial of service via connection exhaustion, and potential SSRF via WebSocket upgrade handling. 👉 Affected: next (npm) | Fix: Monitor vendor advisories and upgrade to patched versions

    Post summary

    The text announces multiple newly identified Next.js CVEs, detailing their technical impacts and advising users to monitor vendor advisories for patches.

    10030283
    187 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Next.js に 5 件の深刻な脆弱性が FIX:DoS/SSRF/認証バイパスに対応 https://iototsecnews.jp/2026/05/08/multiple-critical-flaws-fixed-in-next-js-and-react-server-components/ 今回の脆弱性の主な原因は、リクエストの処理過程における検証不足や予期しない挙動にあります。たとえば CVE-2026-44575/CVE-2026-44574/CVE-2026-44573 では、特定の URL やパラメータを細工することで、ミドルウェアによる認証チェックが回避されてしまいます。 また、CVE-2026-23870/CVE-2026-44579 は、データの復元処理やリクエスト処理の不備が CPU の過負荷やデッドロックを引き起こし、サービス停止を招くものです。 さらに CVE-2026-44578 では WebSocket の仕組みを悪用した不正な通信の中継が問題となりました。ご利用のチームは、ご注意ください。 #CVE202623870 #CVE202644573 #CVE202644574 #CVE202644575 #CVE202644579 #Nextjs #Vulnerability

    Post summary

    The post announces that five critical CVEs in Next.js have been fixed, describing the vulnerability types and urging users to apply the available patches.

    01000184
    489 followersView on X
  • Hacking Team@HackingTeam77
    PoC

    next-16.2.4-pocs Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-445... https://github.com/dwisiswant0/next-16.2.4-pocs #exploit

    Post summary

    The post announces a GitHub repository that publishes Proof‑of‑Concept code for several CVEs affecting Next.js v16.2.4, without mentioning patches, mitigation steps, or active exploitation.

    01000342
    1.6K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Next.js ❗ CVE-2026-44578 ❗ CVE-2026-44574 ❗ CVE-2026-44573 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-next-js/ https://t.co/xSWb6rTBgI

    Post summary

    Three CVE identifiers for Next.js vulnerabilities are announced, with a link to a CERT webpage for more details; no evidence of PoC, exploit, active use, patches, or technical specifics is presented.

    00000258
    6.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvercelnext.js-node.js-

Explore more