S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated May 15, 2026

CVE-2026-44578 Scanner

CVE-2026-44578 Scanner - Server-Side-Request-Forgery (SSRF) vulnerability in Next.js

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.9k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-44578
8.6
CVSShigh
Exploitable remotely over the internet · no authentication required.

Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed in 15.5.16 and 16.2.5.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
next.jsby vercel
>= 16.0.0, < 16.2.5
Streams for Apache Kafka 2.9.4by Red Hat
Red Hat Trusted Artifact Signer 1.3by Red Hat
AFFECTED< *SAFE ✓≥ *
Red Hat Trusted Artifact Signer 1.4by Red Hat
AFFECTED< *SAFE ✓≥ *
Updated Aug 21, 2026View on NVD →
Detail

Next.js is a popular web development framework developed by Vercel, widely utilized by developers for building server-side rendered React applications. Its simplicity and flexibility have made it a go-to choice for both small and large scale web projects. Developers of various expertise levels leverage it for its powerful features such as automatic code splitting, static site generation, and API support. The framework is an integral tool for web developers seeking to create high-performance, SEO-friendly web applications. Companies often rely on Next.js to produce dynamic, scalable websites and applications that improve user experience and engagement. Next.js continues to innovate, continuously expanding its functionalities and integration capabilities with other technologies.

Server-side request forgery (SSRF) is a critical vulnerability that occurs when an attacker manipulates a server into making requests to unintended locations. SSRF vulnerabilities are dangerous because they can be used to probe and interact with otherwise inaccessible internal services or network segments. This weakness can also be exploited to retrieve sensitive metadata information from cloud service providers' endpoints. In the context of Next.js, SSRF vulnerabilities allow attackers to craft malicious WebSocket upgrade requests to force the Node.js server to proxy requests to arbitrary destinations. This type of vulnerability poses significant security risks as attackers bypass typical security mechanisms, leading to unauthorized access and potential exploitation of internal resources.

This specific SSRF vulnerability in Next.js emerges due to the handling of WebSocket upgrade requests in the Node.js server component. By utilizing crafted WebSocket headers, attackers are able to manipulate the server into forwarding requests to both internal and external services. The vulnerability is particularly severe as it enables proxying to cloud metadata endpoints, a common target for SSRF attacks. Attackers can construct request payloads containing malicious URLs or headers in order to extract sensitive information or perform further enumeration. Key parameters manipulated during the SSRF attempt include the 'Host' and 'Upgrade' headers within the HTTP requests. Vigilance is required to detect malicious attempts and prevent exploitation through proper configuration and version updates.

The exploitation of this SSRF vulnerability in Next.js could lead to grave security implications. If an attacker successfully leverages this vulnerability, they can access sensitive internal resources not publicly exposed on the internet. This could include confidential data, internal applications, and metadata services on cloud platforms. Unintended access may potentially help attackers enumerate and map internal network structures, laying the groundwork for subsequent attacks. Additionally, it could result in unauthorized data disclosure or manipulation, degrading trust and security integrity of the affected application. Attackers might also pivot from this entry point to launch further attacks such as privilege escalation or lateral movement within the network.

REFERENCES

Solution Advice
  • Upgrade to the latest version of Next.js as recommended by the developers to patch the vulnerability.
  • Regularly review and audit WebSocket configurations for security best practices.
  • Ensure proper access controls and firewall restrictions on internal services and networks.
  • Consider using additional security layers such as Web Application Firewalls (WAF) to protect against SSRF attacks.
  • Monitor and log any unexpected network activities for potential unauthorized access attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.