CVE-2026-44578: CWE-918: Server-Side Request Forgery (SSRF) in vercel next.js
Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed in 15.5.16 and 16.2.5.
AI Analysis
Technical Summary
CVE-2026-44578 is a Server-Side Request Forgery (SSRF) vulnerability in Next.js affecting self-hosted applications using the built-in Node.js server. The flaw arises from the server's handling of crafted WebSocket upgrade requests, which can be exploited by remote attackers to make the server proxy requests to arbitrary internal or external destinations. This can lead to exposure of internal network services or sensitive cloud metadata endpoints. The vulnerability affects Next.js versions >=13.4.13 <15.5.16 and >=16.0.0 <16.2.5. Vercel-hosted deployments are not vulnerable. The vulnerability has a CVSS v3.1 base score of 8.6 (high severity) with network attack vector, low complexity, no privileges required, no user interaction, and a changed scope with high confidentiality impact. Red Hat advisories confirm the vulnerability and note that no suitable mitigation is currently available, recommending upgrading to fixed versions 15.5.16 and 16.2.5.
Potential Impact
An attacker can exploit this SSRF vulnerability to make the vulnerable Next.js server proxy requests to arbitrary destinations, potentially exposing internal services or sensitive cloud metadata endpoints that are otherwise inaccessible. This can lead to confidentiality breaches of internal network resources. The vulnerability does not impact integrity or availability. The attack requires no privileges or user interaction and can be performed remotely over the network.
Mitigation Recommendations
The vulnerability is fixed in Next.js versions 15.5.16 and 16.2.5. Users of affected versions should upgrade to these fixed versions to remediate the issue. Red Hat advisories indicate that no effective mitigation other than upgrading currently meets their criteria. Vercel-hosted deployments are not affected and require no action. Check the vendor advisory for the latest remediation guidance.
CVE-2026-44578: CWE-918: Server-Side Request Forgery (SSRF) in vercel next.js
Description
Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed in 15.5.16 and 16.2.5.
CVSS v3.1
Score 8.6high
Affected software
vercel
next.js
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-44578 is a Server-Side Request Forgery (SSRF) vulnerability in Next.js affecting self-hosted applications using the built-in Node.js server. The flaw arises from the server's handling of crafted WebSocket upgrade requests, which can be exploited by remote attackers to make the server proxy requests to arbitrary internal or external destinations. This can lead to exposure of internal network services or sensitive cloud metadata endpoints. The vulnerability affects Next.js versions >=13.4.13 <15.5.16 and >=16.0.0 <16.2.5. Vercel-hosted deployments are not vulnerable. The vulnerability has a CVSS v3.1 base score of 8.6 (high severity) with network attack vector, low complexity, no privileges required, no user interaction, and a changed scope with high confidentiality impact. Red Hat advisories confirm the vulnerability and note that no suitable mitigation is currently available, recommending upgrading to fixed versions 15.5.16 and 16.2.5.
Potential Impact
An attacker can exploit this SSRF vulnerability to make the vulnerable Next.js server proxy requests to arbitrary destinations, potentially exposing internal services or sensitive cloud metadata endpoints that are otherwise inaccessible. This can lead to confidentiality breaches of internal network resources. The vulnerability does not impact integrity or availability. The attack requires no privileges or user interaction and can be performed remotely over the network.
Mitigation Recommendations
The vulnerability is fixed in Next.js versions 15.5.16 and 16.2.5. Users of affected versions should upgrade to these fixed versions to remediate the issue. Red Hat advisories indicate that no effective mitigation other than upgrading currently meets their criteria. Vercel-hosted deployments are not affected and require no action. Check the vendor advisory for the latest remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-06T21:49:12.424Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-44578","vendor":"Red Hat"}]
Threat ID: 6a04ba22cbff5d8610f482d5
Added to database: 05/13/2026, 17:51:30 UTC
Last enriched: 08/13/2026, 13:04:03 UTC
Last updated: 09/14/2026, 10:01:31 UTC
Views: 118
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.