← Back to browse · API

CVE-2026-44578

Severity
HIGH
CVSS
8.6
EPSS
0.38872
Risk score
48.01
CISA KEV
No
PoC
Yes
Published
2026-05-13
Modified
2026-07-16
First seen
2026-08-07
Aliases
EUVD-2026-30080, GHSA-C4J6-FC7J-M34R
Products
vercel:next.js 13.4.13, < 15.5.16, vercel:next.js 16.0.0, < 16.2.5
Sources
packetstorm e1b15243aca2ad53b47ce4cf|CVE-2026-44578
euvd EUVD-2026-30080

Description

Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed in 15.5.16 and 16.2.5.

References