CVE-2026-44581PoC(vercel / next.js)

MEDIUMCVSS 4.7 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch vercel next.js systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Next.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In affected versions, malformed nonce values derived from request headers could be reflected into rendered HTML in an unsafe way, allowing an attacker to poison cached responses and cause script execution for later visitors. This vulnerability is fixed in 15.5.16 and 16.2.5.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • next.js

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 11 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Peaked 6d ago at 3 mentions (2026-05-07); latest day: 1
  • 11 total mentions across 7 days

Affected systems

Vendors
Products
next.js

Deep dive

Activity timeline11 mentions / 7d
01223Mentions · 2026-05-07: 3Mentions · 2026-05-08: 1Mentions · 2026-05-09: 2Mentions · 2026-05-10: 2Mentions · 2026-05-11: 1Mentions · 2026-05-15: 1Mentions · 2026-05-16: 1PoC Mentioned / Linked · 2026-05-08: 1PoC Mentioned / Linked · 2026-05-09: 2PoC Mentioned / Linked · 2026-05-10: 2PoC Mentioned / Linked · 2026-05-11: 1Exploit Tool / Code · 2026-05-08: 1Exploit Tool / Code · 2026-05-09: 2Exploit Tool / Code · 2026-05-10: 1Exploit Tool / Code · 2026-05-11: 1Patch / Workaround · 2026-05-07: 2Technical Details · 2026-05-07: 2Technical Details · 2026-05-15: 105-0705-0805-0905-1005-1105-1505-16
Signal classification4 categories
PoC
654.5%
General
218.2%
Patch
218.2%
Disclosure
19.1%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-073
General1Patch2
2026-05-081
PoC1
2026-05-092
PoC2
2026-05-102
PoC2
2026-05-111
PoC1
2026-05-151
Disclosure1
2026-05-161
General1
Full discourse11 posts
  • dw1@dwisiswant0
    PoC

    CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572 https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    The message lists multiple CVEs and provides a link to a GitHub repository containing proof‑of‑concept code for exploiting them, with no indications of active exploitation, patches, or detailed vulnerability information.

    4126765045576.6K
    16.0K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    A GitHub repository containing Proof‑of‑Concept code for several Next.js 16.2.4 CVEs is provided, with no mention of active exploitation, patches, or technical details.

    144220813713.7K
    158.6K followersView on X
  • s1r1us (mohan)@S1r1u5_
    Patch

    Next.js v16.2.5 fixes a bunch of vulnerabilities reported by @HacktronAI. Patch ASAP, especially if you’re running self-hosted Next.js that SSRF might affect you CVE-2026-44574: Middleware / Proxy bypass via dynamic route parameter injection CVE-2026-44578: SSRF in applications using WebSocket upgrades CVE-2026-44581: XSS in App Router applications using CSP nonces

    Post summary

    The advisory announces that Next.js v16.2.5 patches three CVEs, urging immediate update and providing technical details of each vulnerability.

    01711417012.8K
    13.7K followersView on X
  • Psycho 🎭@Psycho10k_
    PoC

    Next.js v16.2.4 Security PoC Collection CVE-2026-23870 CVE-2026-44575 CVE-2026-44579 CVE-2026-44574 CVE-2026-44578 CVE-2026-44573 CVE-2026-44581 CVE-2026-44580 CVE-2026-44577 CVE-2026-44576 CVE-2026-44582 CVE-2026-44572 https://github.com/dwisiswant0/next-16.2.4-pocs via: Pr0xy

    Post summary

    The post announces a collection of Proof‑of‑Concept exploits for several CVEs affecting Next.js v16.2.4, providing a GitHub link to the repository.

    08043302.5K
    455 followersView on X
  • Sam Stepanyan@securestep9
    Patch

    #NextJS and #React Server Components hit with 12 vulnerabilities with 3 high-severity vulns (CVE-2026-44574, CVE-2026-44578, CVE-2026-44581) requiring the most urgent attention and impacting virtually every production NextJS deployment - patch now! https://www.cyberkendra.com/2026/05/react-and-nextjs-hit-with-12-security.html

    Post summary

    The post warns of 12 critical vulnerabilities impacting NextJS and React server components—specifically CVE-2026-44574, CVE-2026-44578, and CVE-2026-44581—and urges immediate patching for all affected deployments.

    018042193.7K
    7.4K followersView on X
  • termireum@termireum
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    The post announces a GitHub repository containing proof‑of‑concept exploits for several Next.js v16.2.4 CVEs, with no mention of active exploitation, patches, or detailed technical information.

    0101810684
    758 followersView on X
  • Harsh Jaiswal@rootxharsh
    Disclosure

    CVE-2026-44581: stored XSS via CSP nonce injection Next.js reads the nonce from your Content-Security-Policy request header and drops it into <script> tags using JSON.stringify(). It escapes " as \", but HTML parsers don't treat \ as an escape, so you break out of the attribute and inject src=//evil.com/xss.js. This is self-xss on Vercel (since response is private, no-cache). But on self-hosted deployments with ISR (next start), the first request poisons the ISR file cache for everyone, resulting in stored XSS. The same goes for setups behind nginx/Cloudflare that cache the origin response.

    Post summary

    The post outlines the technical details of CVE-2026-44581, a stored XSS flaw caused by CSP nonce injection, but does not provide a PoC, exploit tool, evidence of active exploitation, or a patch.

    1301061.7K
    22.4K followersView on X
  • Huda Al-Assaf@0x0Huda
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    A collection of Proof‑of‑Concept code for multiple Next.js v16.2.4 vulnerabilities, hosted on GitHub, is shared without evidence of active exploitation or patches.

    020543.0K
    727 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-44581 2 - CVE-2026-45185 3 - CVE-2026-44578 4 - CVE-2026-20182 5 - CVE-2026-42945 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    This post lists the top 5 trending CVEs and links to a dashboard, but offers no technical, exploit, or mitigation details.

    00012219
    1.7K followersView on X
  • Cyber Kendra@cyberkendra
    General

    CVE-2026-44581 — XSS through CSP nonces. CSP nonces exist specifically to stop XSS. This flaw weaponizes that protection against users. Irony at its worst.

    Post summary

    The text announces CVE‑2026‑44581 as an XSS vulnerability that subverts CSP nonces, but offers no additional details such as exploitation evidence, PoC, or patches.

    2000098
    1.5K followersView on X
  • Hacking Team@HackingTeam77
    PoC

    next-16.2.4-pocs Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-445... https://github.com/dwisiswant0/next-16.2.4-pocs #exploit

    Post summary

    A GitHub repository hosts PoCs for several Next.js v16.2.4 CVEs, indicating proof‑of‑concept availability but no evidence of active exploitation or patching.

    01000342
    1.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvercelnext.js-node.js-

Explore more