CVE-2026-44574PoC(vercel / next.js)

MEDIUMCVSS 8.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch vercel next.js systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specially crafted query parameters can alter the dynamic route value seen by the page while leaving the visible path unchanged, which can allow protected content to be rendered without passing the expected middleware check. This vulnerability is fixed in 15.5.16 and 16.2.5.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288CWE-551

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • next.js

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 16 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • Peaked 8d ago at 4 mentions (2026-05-07); latest day: 1
  • 16 total mentions across 9 days

Affected systems

Vendors
Products
next.js

Deep dive

Activity timeline16 mentions / 9d
01234Mentions · 2026-05-07: 4Mentions · 2026-05-08: 1Mentions · 2026-05-09: 2Mentions · 2026-05-10: 2Mentions · 2026-05-11: 2Mentions · 2026-05-12: 1Mentions · 2026-05-14: 1Mentions · 2026-05-15: 2Mentions · 2026-05-26: 1PoC Mentioned / Linked · 2026-05-08: 1PoC Mentioned / Linked · 2026-05-09: 2PoC Mentioned / Linked · 2026-05-10: 2PoC Mentioned / Linked · 2026-05-11: 1Exploit Tool / Code · 2026-05-08: 1Exploit Tool / Code · 2026-05-09: 2Exploit Tool / Code · 2026-05-10: 2Patch / Workaround · 2026-05-07: 3Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-05-15: 1Technical Details · 2026-05-07: 4Technical Details · 2026-05-11: 1Technical Details · 2026-05-15: 205-0705-0805-0905-1005-1105-1205-1405-1505-26
Signal classification4 categories
PoC
637.5%
Disclosure
531.3%
Patch
318.8%
General
212.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-05-074
Disclosure3Patch1
2026-05-081
PoC1
2026-05-092
PoC2
2026-05-102
PoC2
2026-05-112
Disclosure1PoC1
2026-05-121
General1
2026-05-141
Patch1
2026-05-152
Disclosure1Patch1
2026-05-261
General1
Full discourse16 posts
  • dw1@dwisiswant0
    PoC

    CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572 https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    A list of multiple CVEs is provided along with a GitHub link pointing to Proof of Concept code for these issues.

    4126765045576.6K
    16.0K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    The provided text announces a collection of PoCs for multiple Next.js CVEs, offering a GitHub link for the code, but it does not discuss active exploitation, patching, or technical vulnerability details.

    144220813713.7K
    158.6K followersView on X
  • s1r1us (mohan)@S1r1u5_
    Disclosure

    Next.js v16.2.5 fixes a bunch of vulnerabilities reported by @HacktronAI. Patch ASAP, especially if you’re running self-hosted Next.js that SSRF might affect you CVE-2026-44574: Middleware / Proxy bypass via dynamic route parameter injection CVE-2026-44578: SSRF in applications using WebSocket upgrades CVE-2026-44581: XSS in App Router applications using CSP nonces

    Post summary

    Next.js v16.2.5 releases patches for three CVEs (44574, 44578, 44581) covering a middleware bypass, an SSRF via WebSocket upgrade, and an XSS attack exploiting CSP nonces; patching is urgently recommended, especially for self-hosted installations.

    01711417012.8K
    13.7K followersView on X
  • Psycho 🎭@Psycho10k_
    PoC

    Next.js v16.2.4 Security PoC Collection CVE-2026-23870 CVE-2026-44575 CVE-2026-44579 CVE-2026-44574 CVE-2026-44578 CVE-2026-44573 CVE-2026-44581 CVE-2026-44580 CVE-2026-44577 CVE-2026-44576 CVE-2026-44582 CVE-2026-44572 https://github.com/dwisiswant0/next-16.2.4-pocs via: Pr0xy

    Post summary

    The post announces a collection of Proof of Concept code for several CVEs affecting Next.js v16.2.4, providing a GitHub repository link, but offers no additional technical details, patches, or evidence of active exploitation.

    08043302.5K
    455 followersView on X
  • Sam Stepanyan@securestep9
    Patch

    #NextJS and #React Server Components hit with 12 vulnerabilities with 3 high-severity vulns (CVE-2026-44574, CVE-2026-44578, CVE-2026-44581) requiring the most urgent attention and impacting virtually every production NextJS deployment - patch now! https://www.cyberkendra.com/2026/05/react-and-nextjs-hit-with-12-security.html

    Post summary

    The post announces 12 vulnerabilities—3 of high severity—in NextJS and React Server Components and urges immediate patching of affected deployments.

    018042193.7K
    7.4K followersView on X
  • termireum@termireum
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    A GitHub repository has been released that provides Proof of Concept code for multiple Next.js v16.2.4 CVEs, but no further exploitation or mitigation details are mentioned.

    0101810684
    758 followersView on X
  • Harsh Jaiswal@rootxharsh
    Disclosure

    CVE-2026-44574: Middleware auth bypass via internal query params. Next.js uses internal query params nxtP<param> and nxtI<param> to pass resolved dynamic route params from routing to route modules. they're never stripped from external requests, leading to middleware bypass in dynamic routes.

    Post summary

    CVE‑2026‑44574 reveals a middleware authentication bypass in Next.js caused by internal query parameters that are not stripped from external requests, allowing unauthorized access to dynamic routes.

    1601151.8K
    22.4K followersView on X
  • Huda Al-Assaf@0x0Huda
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    A GitHub repository containing Proof of Concept code for multiple Next.js v16.2.4 CVEs is referenced, showing the availability of PoC but no discussion of active exploitation, patches, or technical details.

    020543.0K
    727 followersView on X
  • oyamon@oyamon_dev
    Disclosure

    いよいよAIの強力な脆弱性チェックの成果が出てきたな。 Next.js v16.2.6リリース。セキュリティ修正が13件もあるのでメモ。 対象バージョンは以下の両者。 ・v15.x < 15.5.16 ・v16.0.0 〜 v16.2.5 【High】 1. GHSA-492v-c6pp-mqqv (CVSS 8.1 / CVE-2026-44574) 動的ルートパラメータ注入によるミドルウェアバイパス。クエリで動的ルート値を改変し、URLは変えずに認可をすり抜けられる。App Router・15.4.0以降。 2. GHSA-c4j6-fc7j-m34r (CVSS 8.6) WebSocket upgrade経由のSSRF。内部サービスやクラウドメタデータにプロクシされる可能性。セルフホストのみ、Vercelは対象外。 3. GHSA-267c-6grr-h53f (CVSS 7.5) segment-prefetchルート経由のミドルウェアバイパス。.rscやprefetchリクエストがミドルウェアをスキップして同じページに到達。 4. GHSA-26hh-7cqf-hhc6 上記#3の不完全修正に対する追加パッチ。 5. GHSA-36qx-fr4f-26g5 Pages Router + i18nでのミドルウェアバイパス。 6. GHSA-8h8q-6873-q5fj Server ComponentsのDoS脆弱性。 7. GHSA-mg66-mrh9-m8jx Cache Components使用アプリでのコネクション枯渇によるDoS。 【Moderate】 8. GHSA-ffhc-5mcf-pf4q App Router + CSP nonce使用時のXSS。 9. GHSA-gx5p-jg67-6x7h beforeInteractive scriptsに信頼できない入力が渡るケースでのXSS。 10. GHSA-h64f-5h5j-jqjh Image Optimization APIの DoS。 11. GHSA-wfc6-r584-vfw7 React Server Componentレスポンスのキャッシュポイズニング。 【Low】 12. GHSA-vfv6-92ff-j949 RSCのキャッシュバスティング衰突を起点としたキャッシュポイズニング。 13. GHSA-3g8h-86w9-wvmq ミドルウェアのリダイレクトがキャッシュポイズンされる。 ミドルウェアだけで認可しているケースは、未認証で保護コンテンツに到達されるリスクあり。アップデートを推奨。 自分のプロダクトではここまでmiddlewareでの認証、認可に頼らず基本pageで認証認可していて、middlewareは未ログイン時のredirectのみなので、そこは安心。 https://github.com/vercel/next.js/releases/tag/v16.2.6

    Post summary

    The release notes detail the Next.js v16.2.6 update, listing 13 patched CVEs with technical details and patches, but contain no PoC, exploit code, active exploitation alerts, or false positive claims.

    10031941
    300 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 High - Next.js Multiple Vulnerabilities (CVE-2026-44573, CVE-2026-44574, CVE-2026-44575, CVE-2026-44578, CVE-2026-44579, CVE-2026-45109) Multiple issues were identified in Next.js affecting App Router, Pages Router, Server Components, WebSockets, and caching mechanisms. These include middleware/proxy bypasses, denial of service via connection exhaustion, and potential SSRF via WebSocket upgrade handling. 👉 Affected: next (npm) | Fix: Monitor vendor advisories and upgrade to patched versions

    Post summary

    The post announces multiple high‑severity vulnerabilities in Next.js, detailing the affected components and exploitation vectors, and advises applying vendor patches.

    10030283
    187 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Next.js に 5 件の深刻な脆弱性が FIX:DoS/SSRF/認証バイパスに対応 https://iototsecnews.jp/2026/05/08/multiple-critical-flaws-fixed-in-next-js-and-react-server-components/ 今回の脆弱性の主な原因は、リクエストの処理過程における検証不足や予期しない挙動にあります。たとえば CVE-2026-44575/CVE-2026-44574/CVE-2026-44573 では、特定の URL やパラメータを細工することで、ミドルウェアによる認証チェックが回避されてしまいます。 また、CVE-2026-23870/CVE-2026-44579 は、データの復元処理やリクエスト処理の不備が CPU の過負荷やデッドロックを引き起こし、サービス停止を招くものです。 さらに CVE-2026-44578 では WebSocket の仕組みを悪用した不正な通信の中継が問題となりました。ご利用のチームは、ご注意ください。 #CVE202623870 #CVE202644573 #CVE202644574 #CVE202644575 #CVE202644579 #Nextjs #Vulnerability

    Post summary

    The post announces that five critical Next.js CVEs have been fixed and provides the CVE IDs along with brief technical descriptions of each flaw.

    01000184
    489 followersView on X
  • Hacking Team@HackingTeam77
    PoC

    next-16.2.4-pocs Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-445... https://github.com/dwisiswant0/next-16.2.4-pocs #exploit

    Post summary

    A GitHub repository hosts a collection of Proof‑of‑Concept exploits for multiple CVEs in Next.js v16.2.4, but there is no evidence of active exploitation, patches, or detailed technical information.

    01000342
    1.6K followersView on X
  • Cyber Kendra@cyberkendra
    Disclosure

    CVE-2026-44574 — Middleware bypass via dynamic route injection. Middleware is how most Next.js apps check if you're logged in. This flaw lets attackers skip that check entirely. No WAF can safely block it without breaking your app.

    Post summary

    CVE-2026-44574 exposes a middleware bypass in Next.js applications through dynamic route injection, allowing attackers to evade login checks. No WAF can block the vulnerability without breaking the app, and no patch or exploit code is referenced.

    10000112
    1.5K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-44574: Next.js Middleware Authorization Bypass - What It Means for Your Business and How to Respond https://hubs.ly/Q04hSXMX0

    Post summary

    The text cites a Next.js Middleware Authorization Bypass (CVE-2026‑44574) but offers no concrete details about exploits, patches, or active use, merely hinting at a discussion on business impact and response.

    0000042
    31 followersView on X
  • fujiback@oTheRwoRldy
    Patch

    直近のNext.jsのリリースで対応された脆弱性は記事を見るにこのあたりのことかな👀 CVE-2026-44574 CVE-2026-44575 CVE-2026-23870 CVE-2026-44578 CVE-2026-44579 Multiple Critical Vulnerabilities Patched in Next.js and React Server Components https://cyberpress.org/vulnerabilities-patched-in-next-js-and-react/

    Post summary

    The article reports that several critical Next.js/React Server Components vulnerabilities (CVE-2026-44574, 2026-44575, 2026-23870, 2026-44578, 2026-44579) have been patched, but it does not provide PoC, exploitation details, or evidence of active attacks.

    00000355
    1.0K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Next.js ❗ CVE-2026-44578 ❗ CVE-2026-44574 ❗ CVE-2026-44573 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-next-js/ https://t.co/xSWb6rTBgI

    Post summary

    The tweet lists three new CVEs affecting Next.js and directs readers to external links for more information without providing technical details, PoC, or patch information.

    00000258
    6.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvercelnext.js-node.js-

Explore more