CVE-2026-44579PoC(vercel / next.js)

MEDIUMCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch vercel next.js systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurations, a malicious request can trigger a request-body handling deadlock that leaves connections open for an extended period, consuming file descriptors and server capacity until legitimate users are denied service. This vulnerability is fixed in 15.5.16 and 16.2.5.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770CWE-833

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • next.js

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 10 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-05-10); latest day: 1
  • 10 total mentions across 6 days

Affected systems

Vendors
Products
next.js

Deep dive

Activity timeline10 mentions / 6d
01223Mentions · 2026-05-08: 1Mentions · 2026-05-09: 2Mentions · 2026-05-10: 3Mentions · 2026-05-11: 2Mentions · 2026-05-14: 1Mentions · 2026-05-15: 1PoC Mentioned / Linked · 2026-05-08: 1PoC Mentioned / Linked · 2026-05-09: 2PoC Mentioned / Linked · 2026-05-10: 3PoC Mentioned / Linked · 2026-05-11: 1Exploit Tool / Code · 2026-05-10: 3Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-05-15: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-15: 105-0805-0905-1005-1105-1405-15
Signal classification3 categories
PoC
770.0%
Patch
220.0%
Disclosure
110.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-081
PoC1
2026-05-092
PoC2
2026-05-103
PoC3
2026-05-112
Disclosure1PoC1
2026-05-141
Patch1
2026-05-151
Patch1
Full discourse10 posts
  • dw1@dwisiswant0
    PoC

    CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572 https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    The message lists multiple CVEs and provides a GitHub link to a repository containing proof‑of‑concept files for Next.js v16.2.4, indicating that PoC code is available.

    4126765045576.6K
    16.0K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    The post shares a GitHub repository hosting proof‑of‑concept code for multiple CVE‑listed vulnerabilities in Next.js v16.2.4, with no evidence of active exploitation or patch information.

    144220813713.7K
    158.6K followersView on X
  • Psycho 🎭@Psycho10k_
    PoC

    Next.js v16.2.4 Security PoC Collection CVE-2026-23870 CVE-2026-44575 CVE-2026-44579 CVE-2026-44574 CVE-2026-44578 CVE-2026-44573 CVE-2026-44581 CVE-2026-44580 CVE-2026-44577 CVE-2026-44576 CVE-2026-44582 CVE-2026-44572 https://github.com/dwisiswant0/next-16.2.4-pocs via: Pr0xy

    Post summary

    This post announces a GitHub collection of proofs of concept for multiple CVEs affecting Next.js v16.2.4, providing links but no exploits, patches, or evidence of active exploitation.

    08043302.5K
    455 followersView on X
  • termireum@termireum
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    A GitHub repository offering Proof‑of‑Concept code for a set of Next.js v16.2.4 CVEs is announced.

    0101810684
    758 followersView on X
  • Huda Al-Assaf@0x0Huda
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    The post announces a GitHub repository containing proof‑of‑concept code for multiple Next.js 16.2.4 CVEs, with no mention of active exploitation or patches.

    020543.0K
    727 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 High - Next.js Multiple Vulnerabilities (CVE-2026-44573, CVE-2026-44574, CVE-2026-44575, CVE-2026-44578, CVE-2026-44579, CVE-2026-45109) Multiple issues were identified in Next.js affecting App Router, Pages Router, Server Components, WebSockets, and caching mechanisms. These include middleware/proxy bypasses, denial of service via connection exhaustion, and potential SSRF via WebSocket upgrade handling. 👉 Affected: next (npm) | Fix: Monitor vendor advisories and upgrade to patched versions

    Post summary

    The tweet announces multiple high‑severity CVEs in Next.js that affect router functionality, server components, WebSockets, and caching, highlighting bypasses, DoS, and SSRF risks, and urges users to update to patched versions.

    10030283
    187 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Next.js に 5 件の深刻な脆弱性が FIX:DoS/SSRF/認証バイパスに対応 https://iototsecnews.jp/2026/05/08/multiple-critical-flaws-fixed-in-next-js-and-react-server-components/ 今回の脆弱性の主な原因は、リクエストの処理過程における検証不足や予期しない挙動にあります。たとえば CVE-2026-44575/CVE-2026-44574/CVE-2026-44573 では、特定の URL やパラメータを細工することで、ミドルウェアによる認証チェックが回避されてしまいます。 また、CVE-2026-23870/CVE-2026-44579 は、データの復元処理やリクエスト処理の不備が CPU の過負荷やデッドロックを引き起こし、サービス停止を招くものです。 さらに CVE-2026-44578 では WebSocket の仕組みを悪用した不正な通信の中継が問題となりました。ご利用のチームは、ご注意ください。 #CVE202623870 #CVE202644573 #CVE202644574 #CVE202644575 #CVE202644579 #Nextjs #Vulnerability

    Post summary

    A Japanese security news article announces that multiple critical vulnerabilities in Next.js have been fixed, outlining their causes and exploitation vectors while confirming patches are available.

    01000184
    489 followersView on X
  • Hacking Team@HackingTeam77
    PoC

    next-16.2.4-pocs Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-445... https://github.com/dwisiswant0/next-16.2.4-pocs #exploit

    Post summary

    The post announces a repository containing proof‑of‑concept exploits for several Next.js v16.2.4 CVEs, providing a GitHub link to the PoC collection.

    01000342
    1.6K followersView on X
  • fujiback@oTheRwoRldy
    Patch

    直近のNext.jsのリリースで対応された脆弱性は記事を見るにこのあたりのことかな👀 CVE-2026-44574 CVE-2026-44575 CVE-2026-23870 CVE-2026-44578 CVE-2026-44579 Multiple Critical Vulnerabilities Patched in Next.js and React Server Components https://cyberpress.org/vulnerabilities-patched-in-next-js-and-react/

    Post summary

    The article notes that several critical CVEs—CVE‑2026‑44574, ‑44575, ‑23870, ‑44578, and ‑44579—have been patched in recent Next.js and React Server Components releases.

    00000355
    1.0K followersView on X
  • ✪ 𝕱𝖆𝖍𝖆𝖉@fad_777
    PoC

    مجموعة نقاط الضعف الأمنية لـ Next.js v16.2.4 (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579، وغيرها). التفاصيل في الرابط. Next.js v16.2.4 Security PoC Collection addresses multiple vulnerabilities (CVE-2026-23870, CVE-2026-44575, and others). Explore the full list for in-depth understanding. https://github.com/dwisiswant0/next-16.2.4-pocs #NextJS #CyberSecurity #VulnerabilityManagement

    Post summary

    A GitHub repository provides Proof of Concept exploits for several CVEs affecting Next.js v16.2.4, with no indication of active exploitation or mitigation advice.

    0000067
    66 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvercelnext.js-node.js-

Explore more