CVE 8.6 HIGH

Next.js: Server-side request forgery in applications using WebSocket upgrades_CVE-2026-44578

8.6 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Description

Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed in 15.5.16 and 16.2.5.

AI Analysis

Server-side request forgery vulnerability in Next.js applications using WebSocket upgrades

Basic Information

ID CVE-2026-44578
Source GitHub_M
Published May 13, 2026 at 17:01

Affected Product

Vendor vercel
Product next.js
Version >= 16.0.0, < 16.2.5
Affected Versions vercel next.js >= 16.0.0, < 16.2.5
vercel next.js >= 13.4.13, < 15.5.16

CWE Classification

AI Assessment

AI Score 8.6 / 10
AI Severity High
Vendor Vercel
Product Next.js
Version 13.4.13 to 15.5.15, 16.0.0 to 16.2.4

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.