
🚨 High - Next.js Multiple Vulnerabilities (CVE-2026-44573, CVE-2026-44574, CVE-2026-44575, CVE-2026-44578, CVE-2026-44579, CVE-2026-45109) Multiple issues were identified in Next.js affecting App Router, Pages Router, Server Components, WebSockets, and caching mechanisms. These include middleware/proxy bypasses, denial of service via connection exhaustion, and potential SSRF via WebSocket upgrade handling. 👉 Affected: next (npm) | Fix: Monitor vendor advisories and upgrade to patched versions
Post summary
The tweet announces the discovery of multiple high‑severity vulnerabilities in Next.js, providing technical details and recommending that users monitor vendor advisories and upgrade to patched versions.


