CVE-2026-44575PoC(vercel / next.js)

MEDIUMCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch vercel next.js systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetching. In affected configurations, specially crafted .rsc and segment-prefetch URLs can resolve to the same page without being matched by the intended middleware rule, which can allow protected content to be reached without the expected authorization check. This vulnerability is fixed in 15.5.16 and 16.2.5.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288CWE-551

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • next.js

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 10 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 3 mentions (2026-05-10); latest day: 1
  • 10 total mentions across 6 days

Affected systems

Vendors
Products
next.js

Deep dive

Activity timeline10 mentions / 6d
01223Mentions · 2026-05-08: 1Mentions · 2026-05-09: 2Mentions · 2026-05-10: 3Mentions · 2026-05-11: 2Mentions · 2026-05-14: 1Mentions · 2026-05-15: 1PoC Mentioned / Linked · 2026-05-08: 1PoC Mentioned / Linked · 2026-05-09: 2PoC Mentioned / Linked · 2026-05-10: 3PoC Mentioned / Linked · 2026-05-11: 1Exploit Tool / Code · 2026-05-09: 2Exploit Tool / Code · 2026-05-10: 3Exploit Tool / Code · 2026-05-11: 1Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-05-14: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-15: 105-0805-0905-1005-1105-1405-15
Signal classification3 categories
PoC
770.0%
Disclosure
220.0%
Patch
110.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-081
PoC1
2026-05-092
PoC2
2026-05-103
PoC3
2026-05-112
Disclosure1PoC1
2026-05-141
Patch1
2026-05-151
Disclosure1
Full discourse10 posts
  • dw1@dwisiswant0
    PoC

    CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572 https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    The post lists several CVEs and links to a GitHub repository that contains proof‑of‑concept code for those vulnerabilities.

    4126765045576.6K
    16.0K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    The post announces a GitHub repository that hosts proof‑of‑concept exploits for a number of CVEs affecting Next.js v16.2.4.

    144220813713.7K
    158.6K followersView on X
  • Psycho 🎭@Psycho10k_
    PoC

    Next.js v16.2.4 Security PoC Collection CVE-2026-23870 CVE-2026-44575 CVE-2026-44579 CVE-2026-44574 CVE-2026-44578 CVE-2026-44573 CVE-2026-44581 CVE-2026-44580 CVE-2026-44577 CVE-2026-44576 CVE-2026-44582 CVE-2026-44572 https://github.com/dwisiswant0/next-16.2.4-pocs via: Pr0xy

    Post summary

    A collection of proof‑of‑concept code for multiple Next.js 16.2.4 CVEs has been shared via GitHub, but no evidence of active exploitation, patches, or detailed technical data is included.

    08043302.5K
    455 followersView on X
  • termireum@termireum
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    The post announces a GitHub repository containing proof‑of‑concept exploit files for multiple CVEs in Next.js v16.2.4, without claiming active exploitation or presenting patches.

    0101810684
    758 followersView on X
  • Huda Al-Assaf@0x0Huda
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    The text references a GitHub repository hosting Proof‑of‑Concept code for several Next.js CVEs, confirming the existence of exploitable demos but no evidence of active attacks or mitigation.

    020543.0K
    727 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 High - Next.js Multiple Vulnerabilities (CVE-2026-44573, CVE-2026-44574, CVE-2026-44575, CVE-2026-44578, CVE-2026-44579, CVE-2026-45109) Multiple issues were identified in Next.js affecting App Router, Pages Router, Server Components, WebSockets, and caching mechanisms. These include middleware/proxy bypasses, denial of service via connection exhaustion, and potential SSRF via WebSocket upgrade handling. 👉 Affected: next (npm) | Fix: Monitor vendor advisories and upgrade to patched versions

    Post summary

    Multiple high‑severity Next.js vulnerabilities allowing middleware bypasses, DoS, or SSRF are disclosed; vendors are urged to patch by updating to the latest versions.

    10030283
    187 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Next.js に 5 件の深刻な脆弱性が FIX:DoS/SSRF/認証バイパスに対応 https://iototsecnews.jp/2026/05/08/multiple-critical-flaws-fixed-in-next-js-and-react-server-components/ 今回の脆弱性の主な原因は、リクエストの処理過程における検証不足や予期しない挙動にあります。たとえば CVE-2026-44575/CVE-2026-44574/CVE-2026-44573 では、特定の URL やパラメータを細工することで、ミドルウェアによる認証チェックが回避されてしまいます。 また、CVE-2026-23870/CVE-2026-44579 は、データの復元処理やリクエスト処理の不備が CPU の過負荷やデッドロックを引き起こし、サービス停止を招くものです。 さらに CVE-2026-44578 では WebSocket の仕組みを悪用した不正な通信の中継が問題となりました。ご利用のチームは、ご注意ください。 #CVE202623870 #CVE202644573 #CVE202644574 #CVE202644575 #CVE202644579 #Nextjs #Vulnerability

    Post summary

    The article discloses five critical vulnerabilities in Next.js affecting DoS, SSRF, and authentication bypass, noting they have been fixed, with detailed technical descriptions of the issues.

    01000184
    489 followersView on X
  • Hacking Team@HackingTeam77
    PoC

    next-16.2.4-pocs Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-445... https://github.com/dwisiswant0/next-16.2.4-pocs #exploit

    Post summary

    The text announces a collection of proof‑of‑concept exploits for several Next.js v16.2.4 CVEs, linking to a GitHub repository, but provides no further details on active exploitation or mitigations.

    01000342
    1.6K followersView on X
  • fujiback@oTheRwoRldy
    Patch

    直近のNext.jsのリリースで対応された脆弱性は記事を見るにこのあたりのことかな👀 CVE-2026-44574 CVE-2026-44575 CVE-2026-23870 CVE-2026-44578 CVE-2026-44579 Multiple Critical Vulnerabilities Patched in Next.js and React Server Components https://cyberpress.org/vulnerabilities-patched-in-next-js-and-react/

    Post summary

    Several critical CVEs (CVE‑2026‑44574, 44575, 23870, 44578, 44579) were addressed and patched in the latest Next.js release, as reported in a CyberPress article on Next.js and React Server Components.

    00000355
    1.0K followersView on X
  • ✪ 𝕱𝖆𝖍𝖆𝖉@fad_777
    PoC

    مجموعة نقاط الضعف الأمنية لـ Next.js v16.2.4 (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579، وغيرها). التفاصيل في الرابط. Next.js v16.2.4 Security PoC Collection addresses multiple vulnerabilities (CVE-2026-23870, CVE-2026-44575, and others). Explore the full list for in-depth understanding. https://github.com/dwisiswant0/next-16.2.4-pocs #NextJS #CyberSecurity #VulnerabilityManagement

    Post summary

    The post announces a GitHub repository containing Proof of Concept code for several CVEs in Next.js v16.2.4, with no mention of active exploitation, patches, or detailed vulnerability information.

    0000067
    66 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvercelnext.js-node.js-

Explore more