CVE-2026-44578
High · CVSS 8.6Next.js — Server-Side Request Forgery (SSRF) via WebSocket upgrade request proxying
- CVSS
- 8.6
- nvd
- EPSS
- 38.9%
- 98th pct
- KEV
- No
- Class
- oss containerizable
- CWE-918, CWE-918
Description
Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed in 15.5.16 and 16.2.5.
Search profile — drives PoC discovery
Ranked PoCs (8) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 175
- ★ 6
- ★ 74
- ★ 5
- ★ 1
- ★ 0
- ★ 0
- ★ 0panchocosil/verify-ghsa-c4j6-fc7j-m34r needs reviewgh_search · Python
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
Affected packages
| npm | next | 13.4.13 → 15.5.16 |
| npm | next | 16.0.0 → 16.2.5 |
References
- https://github.com/vercel/next.js/security/advisories/GHSA-c4j6-fc7j-m34r
- https://access.redhat.com/errata/RHSA-2026:34608
- https://access.redhat.com/errata/RHSA-2026:37272
- https://access.redhat.com/errata/RHSA-2026:40974
- https://access.redhat.com/errata/RHSA-2026:54435
- https://access.redhat.com/security/cve/CVE-2026-44578
- https://bugzilla.redhat.com/show_bug.cgi?id=2477187
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44578.json
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T12:30:14.000Z