PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Network Vulnerabilities·Updated May 15, 2026

Next.js WebSocket Upgrade Handler - SSRF

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
2.2k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-44578
8.6
CVSShigh
Exploitable remotely over the internet · no authentication required.

Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed in 15.5.16 and 16.2.5.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
next.jsby vercel
>= 16.0.0, < 16.2.5
Streams for Apache Kafka 2.9.4by Red Hat
Red Hat Trusted Artifact Signer 1.3by Red Hat
AFFECTED< *SAFE ✓≥ *
Red Hat Trusted Artifact Signer 1.4by Red Hat
AFFECTED< *SAFE ✓≥ *
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.