CVE-2026-44578Patch(vercel / next.js)

CRITICALCVSS 8.6 · HIGH

Exploitation observed; activity peaked at 40 mentions and remains active

Immediate actions

  • Patch vercel next.js systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed in 15.5.16 and 16.2.5.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • next.js

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 88 mentions across 18 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 10 signals
  • PoC mentioned or linked in 17 signals
  • Patch or workaround mentioned in 42 signals
  • Technical details provided in 62 signals
  • Disclosure: 25 classified signals
  • General: 14 classified signals
  • Peaked 10d ago at 40 mentions (2026-05-15); latest day: 1
  • 88 total mentions across 18 days

Affected systems

Vendors
Products
next.js

Deep dive

Activity timeline88 mentions / 18d
010203040Mentions · 2026-05-07: 3Mentions · 2026-05-08: 1Mentions · 2026-05-09: 2Mentions · 2026-05-10: 2Mentions · 2026-05-11: 2Mentions · 2026-05-12: 1Mentions · 2026-05-14: 12Mentions · 2026-05-15: 40Mentions · 2026-05-16: 2Mentions · 2026-05-17: 4Mentions · 2026-05-18: 5Mentions · 2026-05-19: 4Mentions · 2026-05-20: 2Mentions · 2026-05-21: 1Mentions · 2026-05-24: 3Mentions · 2026-05-25: 2Mentions · 2026-05-31: 1Mentions · 2026-06-11: 1PoC Mentioned / Linked · 2026-05-08: 1PoC Mentioned / Linked · 2026-05-09: 2PoC Mentioned / Linked · 2026-05-10: 2PoC Mentioned / Linked · 2026-05-11: 1PoC Mentioned / Linked · 2026-05-15: 8PoC Mentioned / Linked · 2026-05-16: 1PoC Mentioned / Linked · 2026-05-18: 1PoC Mentioned / Linked · 2026-05-20: 1Exploit Tool / Code · 2026-05-08: 1Exploit Tool / Code · 2026-05-09: 1Exploit Tool / Code · 2026-05-10: 2Exploit Tool / Code · 2026-05-15: 4Exploit Tool / Code · 2026-05-16: 1Exploit Tool / Code · 2026-05-18: 1Active Exploitation · 2026-05-15: 2Patch / Workaround · 2026-05-07: 2Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-05-14: 8Patch / Workaround · 2026-05-15: 20Patch / Workaround · 2026-05-17: 2Patch / Workaround · 2026-05-18: 3Patch / Workaround · 2026-05-19: 2Patch / Workaround · 2026-05-20: 1Patch / Workaround · 2026-05-25: 2Patch / Workaround · 2026-06-11: 1Technical Details · 2026-05-07: 2Technical Details · 2026-05-11: 1Technical Details · 2026-05-14: 7Technical Details · 2026-05-15: 32Technical Details · 2026-05-16: 1Technical Details · 2026-05-17: 4Technical Details · 2026-05-18: 4Technical Details · 2026-05-19: 4Technical Details · 2026-05-20: 1Technical Details · 2026-05-21: 1Technical Details · 2026-05-24: 1Technical Details · 2026-05-25: 2Technical Details · 2026-05-31: 1Technical Details · 2026-06-11: 105-0705-0805-0905-1005-1105-1205-1405-1505-1605-1705-1805-1905-2005-2105-2405-2505-3106-11
Signal classification6 categories
Patch
3337.5%
Disclosure
2528.4%
General
1415.9%
PoC
1011.4%
Exploit
55.7%
False Positive
11.1%
Referenced assets40 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-073
Disclosure1Patch2
2026-05-081
PoC1
2026-05-092
PoC2
2026-05-102
PoC2
2026-05-112
Disclosure1PoC1
2026-05-121
Disclosure1
2026-05-1412
Disclosure2False Positive1General3Patch6
2026-05-1540
Disclosure11Exploit4General6Patch17PoC2
2026-05-162
Exploit1General1
2026-05-174
Disclosure2General1Patch1
2026-05-185
Disclosure1Patch3PoC1
2026-05-194
Disclosure4
2026-05-202
Patch1PoC1
2026-05-211
Disclosure1
2026-05-243
Disclosure1General2
2026-05-252
Patch2
2026-05-311
General1
2026-06-111
Patch1
Full discourse20 posts
  • Modat@modat_magnify
    Disclosure

    CVE-2026-44578  ⚠️ Next.js – WebSocket Upgrade SSRF (CVSS 8.6)  A server-side request forgery vulnerability in Next.js allows unauthenticated attackers to force self-hosted instances to make internal HTTP requests via the WebSocket upgrade handler.  By sending a crafted absolute-form HTTP request with Upgrade: websocket headers, attackers can access internal services, cloud metadata endpoints, admin panels, and internal APIs reachable from the Next.js server on port 80. Successful exploitation may expose cloud credentials, API keys, secrets, and configuration data.  Affected: Next.js 13.4.13+, 14.x, 15.x <15.5.16, 16.0.0–16.2.4  Mitigation: Upgrade immediately to 15.5.16 or 16.2.5.   Modat Magnify Query:  technology="Next.js"  The platform:  https://magnify.modat.io/  #threatintel #vulnerability #CVE202644578 #Nextjs #SSRF #WebSocket #CloudSecurity #infosec #Critical #ModatMagnify

    Post summary

    CVE-2026-44578 is a Server‑Side Request Forgery vulnerability in Next.js’s WebSocket upgrade handler, allowing attackers to access internal services; affected versions are listed and mitigated by upgrading to 15.5.16 or 16.2.5.

    744142412.4K1.8K1.5M
    1.7K followersView on X
  • dw1@dwisiswant0
    PoC

    CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572 https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    The post lists multiple CVEs and links to a GitHub repository containing Proof‑of‑Concepts for them, indicating the availability of demonstrative exploit code.

    4126765045576.6K
    16.0K followersView on X
  • Yunus Emre Öztaş@ynsmroztas
    Exploit

    🚨 CVE-2026-44578 — Next.js WebSocket SSRF Built a scanner + interactive exploit shell. AWS credentials exfiltrated in 3 steps: [1/3] Cloud auto-detect → AWS confirmed [2/3] IAM role found: profile [3/3] 🎯 AccessKeyId + SecretKey + Token ✅ Pipeline ready: subfinder | httpx | nextssrf ✅ Zero dependencies (stdlib only) ✅ Interactive shell with auto IAM chain Affected: Next.js 13.4.13 → 15.5.15 Fixed: 15.5.16 / 16.2.5 (self-hosted only) 🔗 https://github.com/ynsmroztas/nextssrf #BugBounty #InfoSec #RedTeam #AppSec #bugbountytip #bugbountytips #infosec #recon

    Post summary

    The post announces a functional exploit tool for CVE-2026-44578 with a linked PoC repository, outlines credential exfiltration steps, and notes available patches.

    586044238324.9K
    7.7K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    A GitHub repository is shared that contains Proof‑of‑Concept code for multiple CVEs affecting Next.js v16.2.4, with no mention of patches or active exploitation.

    144220813713.7K
    158.6K followersView on X
  • Harsh Jaiswal@rootxharsh
    Patch

    Last week's Next.js stable release patches multiple vulnerabilities found by @HacktronAI CVE-2026-44578: SSRF via WebSocket upgrade. It is the most impactful of all, it lets an attacker read internal hosts such as cloud metadata endpoints on self-hosted next.js applications. curl -H "Connection: Upgrade" -H "Upgrade: websocket" \ -H "Sec-WebSocket-Version: 13" \ -H "Sec-WebSocket-Key: dGhlIHNhbXBsZSBub25jZQ==" \ "http://target:3000" \ --request-target "http://169.254.169.254/latest/meta-data/"

    Post summary

    The text announces a patch for Next.js that fixes a serious SSRF issue, while also providing a code snippet that demonstrates how the vulnerability can be exploited.

    633118310917.3K
    22.4K followersView on X
  • s1r1us (mohan)@S1r1u5_
    Patch

    Next.js v16.2.5 fixes a bunch of vulnerabilities reported by @HacktronAI. Patch ASAP, especially if you’re running self-hosted Next.js that SSRF might affect you CVE-2026-44574: Middleware / Proxy bypass via dynamic route parameter injection CVE-2026-44578: SSRF in applications using WebSocket upgrades CVE-2026-44581: XSS in App Router applications using CSP nonces

    Post summary

    The message announces that Next.js v16.2.5 includes fixes for several CVEs and urges users to apply the patch immediately.

    01711417012.8K
    13.7K followersView on X
  • Nicolas Krassas@Dinosn
    Exploit

    CVE-2026-44578: Next.js WebSocket Upgrade SSRF — pre-auth credential theft via localhost:80. Lab + exploit + audit. https://github.com/dinosn/CVE-2026-44578

    Post summary

    The post announces a new SSRF vulnerability (CVE‑2026‑44578) in Next.js that can lead to pre‑authentication credential theft via localhost:80, and it provides a GitHub repo containing a functional exploit and audit. No evidence of active exploitation or patch release is presented.

    0231101586.8K
    158.6K followersView on X
  • Hunter@HunterMapping
    General

    🚨Alert🚨 CVE-2026-44578 (CVSS 8.6) : A Real High-Severity SSRF Vulnerability in Self-Hosted Next.js. 🧐Detail :https://hadrian.io/blog/next-js-websocket-ssrf-unauthenticated-access-to-internal-resources-cve-2026-44578-2 📊 11.5M+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Next.js%22 👇Query HUNTER : http://product.name="Next.js" 📰Refer:https://github.com/vercel/next.js/security/advisories/GHSA-c4j6-fc7j-m34r #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    Alert announces a high‑severity SSRF vulnerability (CVE‑2026‑44578) in self‑hosted Next.js, providing technical details and advisory links but no evidence of active exploitation, PoC, or patch.

    325082336.5K
    26.0K followersView on X
  • Psycho 🎭@Psycho10k_
    PoC

    Next.js v16.2.4 Security PoC Collection CVE-2026-23870 CVE-2026-44575 CVE-2026-44579 CVE-2026-44574 CVE-2026-44578 CVE-2026-44573 CVE-2026-44581 CVE-2026-44580 CVE-2026-44577 CVE-2026-44576 CVE-2026-44582 CVE-2026-44572 https://github.com/dwisiswant0/next-16.2.4-pocs via: Pr0xy

    Post summary

    The post announces a GitHub repository containing Proof‑of‑Concept code for a set of Next.js v16.2.4 CVEs, focusing solely on providing PoC access.

    08043302.5K
    455 followersView on X
  • Sam Stepanyan@securestep9
    Patch

    #NextJS and #React Server Components hit with 12 vulnerabilities with 3 high-severity vulns (CVE-2026-44574, CVE-2026-44578, CVE-2026-44581) requiring the most urgent attention and impacting virtually every production NextJS deployment - patch now! https://www.cyberkendra.com/2026/05/react-and-nextjs-hit-with-12-security.html

    Post summary

    The post announces 12 vulnerabilities in NextJS and React Server Components, urging immediate patching but providing no technical or exploit details beyond the CVE identifiers and severity statement.

    018042193.7K
    7.4K followersView on X
  • Daniel Púa@devploit
    Disclosure

    🚨 New Next.js CVE: CVE-2026-44578. High-severity SSRF via WebSocket Upgrade handling in self-hosted Next.js apps using the built-in Node.js server. Unauthenticated. Network-reachable. CVSS 8.6 High. Vercel-hosted deployments are not affected. If you run Next.js on your own infra, read on 🧵

    Post summary

    A new high‑severity SSRF vulnerability (CVE‑2026‑44578) has been disclosed in self‑hosted Next.js applications, affecting network‑reachable setups but not Vercel‑hosted deployments. No proof‑of‑concept, exploit code, or patch information is provided.

    27138304.0K
    3.1K followersView on X
  • yousukezan@yousukezan
    Patch

    Next.js CVE-2026-44578:WebSocket SSRF(CVSS 8.6)の仕組みと自己ホスト向け緊急対策 https://ai-heartland.com/security/news-nextjs-ssrf-cve-2026-44578/

    Post summary

    The post announces the SSRF vulnerability CVE‑2026‑44578 in Next.js, reports a CVSS score of 8.6, and outlines emergency remediation steps for self‑hosted installations.

    1613894.0K
    14.5K followersView on X
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-44578 (CVSS 8.6): self-hosted Next.js WebSocket SSRF before 15.5.16/16.2.5 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJOZXh0LmpzIg%3D%3D 🎯7M+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="Next.js" 🔖Refer: https://nvd.nist.gov/vuln/detail/CVE-2026-44578 #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The post announces an SSRF vulnerability in self‑hosted Next.js WebSocket (CVE‑2026‑44578) with CVSS 8.6 and references FOFA search results, but provides no PoC, exploit, or patch information.

    1802992.2K
    14.4K followersView on X
  • ثامر الغالي@alghali
    Patch

    ⚠️ ثغرة أمنية حرجة في Next.js (CVE-2026-44578) تسمح ثغرة SSRF للمهاجمين بالوصول إلى خدمات داخلية وحساسة (مثل بيانات Cloud Metadata وAPI Keys) عبر تلاعب بطلبات WebSocket. • الخطورة: 8.6 (High) • الإصدارات المتأثرة: 13.4.13 فما فوق وصولاً إلى 16.2.4 الحل: التحديث فوراً إلى 15.5.16 أو 16.2.5 سارع بتحديث مشاريعك لحماية بياناتك! 🛡️

    Post summary

    The post alerts about CVE-2026-44578, a high‑severity SSRF vulnerability in Next.js that could expose internal data, and urges immediate patching to version 15.5.16 or 16.2.5.

    03121136.4K
    91.0K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Critical SSRF vulnerability CVE-2026-44578 impacts self-hosted Next.js applications. Upgrade to version 15.5.16 or 16.2.5 immediately to block the exploit. #NextJS #SSRF #CVE202644578 #WebSecurity2026 #NodeJS #DevSecOps #AppSec https://meterpreter.org/open-proxy-risk-high-severity-next-js-ssrf-flaw-exposes-cloud-metadata-endpoints/ https://t.co/vLGg8dKkRz

    Post summary

    The tweet alerts to a critical SSRF flaw (CVE‑2026‑44578) in self‑hosted Next.js applications and recommends upgrading to versions 15.5.16 or 16.2.5 to mitigate the risk.

    08018101.3K
    12.5K followersView on X
  • termireum@termireum
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    The message announces a GitHub repository containing Proof of Concept code for several Next.js CVEs, without detailing exploitation methods, active attacks, patches, or technical vulnerabilities.

    0101810684
    758 followersView on X
  • AI Heartland@peaks2314
    Patch

    🚨 Next.js自己ホスト勢、今すぐパッチ案件です。 CVE-2026-44578:認証なしでWebSocketアップグレード経由のSSRFが刺さる脆弱性(CVSS 8.6)。 噛み砕くと、外部の攻撃者がNext.jsサーバを踏み台にして、サーバの内側からHTTPリクエストを撃てます。つまり: ・AWS/GCPメタデータエンドポイント → 一時クレデンシャル抜き取り ・社内管理画面・内部API → 横展開 ・環境変数経由のシークレット流出 影響:13.4.13以降ほぼ全系列(15.x<15.5.16 / 16.0–16.2.4)。Vercelホスティングは無影響、自己ホストのみ。 対応:15.5.16 か 16.2.5 へ即アップグレード。Turbopack利用中なら 15.5.18 / 16.2.6(1段上)が正解。 ステージング・PoC・社内検証環境までちゃんと見てますか?

    Post summary

    The post announces the CVE-2026-44578 SSRF vulnerability in self-hosted Next.js and urges immediate upgrade to specified patched versions.

    13020268.8K
    3.4K followersView on X
  • ojasva meshram@love07oj
    PoC

    @ynsmroztas Thank you for the exploit check my nuclei template for detecting cve-2026-44578 https://github.com/love07oj/nextjs-cve-2026-44578

    Post summary

    The user shares a GitHub link to a nuclei detection template for CVE‑2026‑44578, indicating the existence of a PoC, but no exploit, patch, or technical details are provided.

    000129688
    13 followersView on X
  • 波乗野郎@shojiueda
    General

    今日は定期的に受けている血液検査の日です。いつも通り回復基調で、数値はさらに改善ですわ😤 問診を待っている間、nextjsの脆弱性、CVE-2026-44578 について調べました(これWebSocketを利用して無くても脆弱性が成立するので影響が広いですね) AI時代だから、最近、深刻な脆弱性の発表が続き、世の中で対応するセキュリティエンジニア、インフラエンジニアの我々、お疲れさまです、と思います…

    Post summary

    The user briefly mentions the nextjs vulnerability CVE‑2026‑44578 and comments that it can impact systems even without WebSocket usage, but provides no additional technical, exploit, patch, or exploitation details.

    000200343
    1.7K followersView on X
  • Horizon3.ai@Horizon3ai
    PoC

    🚨 Your Next.js app might be proxying attacker traffic into internal services without you realizing it. Rapid Response test now available for CVE-2026-44578. https://t.co/r7wvkSS40N

    Post summary

    A Rapid Response test for CVE‑2026‑44578 has been released, signaling that proof‑of‑concept material exists, but no active exploitation, patch details, or technical depth are provided.

    14072417
    2.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvercelnext.js-node.js-

Explore more