CVE-2026-44577PoC(vercel / next.js)

LOWCVSS 5.9 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for vercel next.js systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Next.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memory without enforcing a maximum size limit. An attacker could cause out-of-memory conditions by requesting large local assets from the /_next/image endpoint that match the images.localPatterns configuration (by default, all patterns are allowed). This vulnerability is fixed in 15.5.16 and 16.2.5.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • next.js

Threat summary

  • Public PoC and exploit tooling are both present
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 6 signals
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-05-09); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
next.js

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-05-08: 1Mentions · 2026-05-09: 2Mentions · 2026-05-10: 2Mentions · 2026-05-11: 1Mentions · 2026-07-04: 1PoC Mentioned / Linked · 2026-05-08: 1PoC Mentioned / Linked · 2026-05-09: 2PoC Mentioned / Linked · 2026-05-10: 2PoC Mentioned / Linked · 2026-05-11: 1Exploit Tool / Code · 2026-05-09: 2Exploit Tool / Code · 2026-05-10: 2Exploit Tool / Code · 2026-05-11: 1Technical Details · 2026-07-04: 105-0805-0905-1005-1107-04
Signal classification2 categories
PoC
685.7%
Disclosure
114.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-081
PoC1
2026-05-092
PoC2
2026-05-102
PoC2
2026-05-111
PoC1
2026-07-041
Disclosure1
Full discourse7 posts
  • dw1@dwisiswant0
    PoC

    CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572 https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    The post lists multiple CVE identifiers and provides a GitHub link to a repository containing proof‑of‑concept code for those issues. It contains no evidence of active exploitation, patches, or detailed technical vulnerability information.

    4126765045576.6K
    16.0K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    The GitHub repo hosts Proof‑of‑Concept exploits for multiple CVEs affecting Next.js v16.2.4, offering code but no evidence of active exploitation or patches.

    144220813713.7K
    158.6K followersView on X
  • Psycho 🎭@Psycho10k_
    PoC

    Next.js v16.2.4 Security PoC Collection CVE-2026-23870 CVE-2026-44575 CVE-2026-44579 CVE-2026-44574 CVE-2026-44578 CVE-2026-44573 CVE-2026-44581 CVE-2026-44580 CVE-2026-44577 CVE-2026-44576 CVE-2026-44582 CVE-2026-44572 https://github.com/dwisiswant0/next-16.2.4-pocs via: Pr0xy

    Post summary

    A GitHub repo is shared that hosts PoCs for several CVEs linked to Next.js v16.2.4, indicating a focus on proof‑of‑concept exploitation.

    08043302.5K
    455 followersView on X
  • termireum@termireum
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    A GitHub repository has been released that provides Proof‑of‑Concept exploit code for twelve Next.js v16.2.4 CVEs, demonstrating that publicly available code exists for these vulnerabilities.

    0101810684
    758 followersView on X
  • Huda Al-Assaf@0x0Huda
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    A GitHub repository hosts proof‑of‑concept scripts for multiple Next.js v16.2.4 CVEs, confirming PoC availability but lacking details on patches, active exploitation, or technical specifics.

    020543.0K
    727 followersView on X
  • InfiniStrategy@InfiniStrategy
    Disclosure

    Web security is having a brutal month. Chrome's July 1 update patched 382 vulnerabilities, including 15 critical bugs enabling remote code execution. Meanwhile, Next.js faces multiple denial-of-service vulnerabilities affecting versions 13 through 16, with CVE-2026-23870 impacting React Server Components and CVE-2026-44577 targeting the image optimization API. The Spring Framework also revealed a zero-day dubbed Spring4Shell. The scale of these findings reflects a broader reality. As web applications grow more complex, so does their attack surface. Server components, edge functions, and AI integrations have added layers that security audits struggle to keep pace with. Frameworks that prioritize developer speed over defensive defaults are creating technical debt that manifests as vulnerabilities. What stands out is how quickly exploits appear. The Next.js image optimization flaw allows attackers to fetch local images into memory without size limits, crashing self-hosted instances. The Spring4Shell discovery caused immediate confusion as researchers determined whether it was new or related to older issues. InfiniStrategy take: Web development in 2026 demands a security-first mindset, not as an afterthought but as a core engineering principle. The frameworks winning developer adoption are those baking security into their defaults, not bolting it on after exploits surface. For businesses, the lesson is clear. Choosing technology based solely on developer velocity without considering security posture creates liability that compounds over time. The most sustainable web applications are built with defensive architecture from day one, because in today's threat landscape, security is not a feature, it is a foundation. Sources: https://cybersecuritynews.com/chrome-update-fixes-382-vulnerabilities/ https://advisories.gitlab.com/npm/next/GHSA-8h8q-6873-q5fj/ https://www.darkreading.com/application-security/zero-day-vulnerability-discovered-in-java-spring-framework

    Post summary

    The article reports the discovery of several critical vulnerabilities across Chrome, Next.js, and Spring Framework, detailing their nature and impact, but does not provide evidence of active exploitation, PoCs, or specific patches.

    01010233
    10 followersView on X
  • Hacking Team@HackingTeam77
    PoC

    next-16.2.4-pocs Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-445... https://github.com/dwisiswant0/next-16.2.4-pocs #exploit

    Post summary

    The post announces a GitHub repository containing PoC code for multiple Next.js CVEs, confirming code availability but lacking active exploitation or patch information.

    01000342
    1.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvercelnext.js-node.js-

Explore more