Skip to content

Information Security News

  • Home
  • Cyber Security
  • Cybercriminals
  • Data Leak
  • Google
    • Android
  • Information Security
  • Linux
  • Malware
  • Microsoft
    • Windows
  • Open Source Tool
  • Vulnerability
  • Technology

Information Security News

  • Home
  • Cyber Security
  • Cybercriminals
  • Data Leak
  • Google
    • Android
  • Information Security
  • Linux
  • Malware
  • Microsoft
    • Windows
  • Open Source Tool
  • Vulnerability
  • Technology
  • Vulnerability

Open Proxy Risk: High-Severity Next.js SSRF Flaw Exposes Cloud Metadata Endpoints

by Nam Phong · May 18, 2026

The development framework Next.js has remediated a critical security vulnerability, designated as CVE-2026-44578, which afflicts applications deployed on self-hosted infrastructure utilizing the embedded Node.js server runtime. The flaw manifests as a Server-Side Request Forgery (SSRF) vector, a vulnerability class that permits an adversary to coerce the vulnerable host into dispatching arbitrary requests toward internal or external network destinations, thereby granting unauthorized access to assets shielded from the public internet. Deployments hosted natively on Vercel remain entirely unaffected.

The core architectural issue stems from the improper validation of incoming WebSocket protocol upgrade headers. An engineered request can manipulate the native Next.js server into functioning as an open proxy, forwarding telemetry to arbitrary endpoints. This behavior exposes internal administrative control panels, restricted service APIs, and cloud provider metadata endpoints—repositories that frequently harbor ephemeral IAM credentials, API bearer tokens, and deployment secrets.

The vulnerability compromises Next.js iterations spanning versions 13.4.13 through 15.5.16 and 16.0.0 through 16.2.5. Definitively patched releases have been deployed in Next.js 15.5.16 and 16.2.5. GitHub has classified the threat profile within the high-severity tier, while the National Vulnerability Database (NVD) maps the issue to CWE-918 with a calculated CVSS base score of 8.6.

Following the implementation of the security patch, Next.js enforces more rigorous validation structures on WebSocket handshake anomalies, effectively blocking arbitrary proxying actions absent explicit, secure routing configurations. Developers managing self-hosted infrastructure are urged to expedite the upgrade of the next package to a remediated version. In scenarios where immediate patch deployment is unfeasible, administrators should suppress protocol upgrade requests at the reverse proxy or load balancer tier, provided the application does not rely on active WebSocket connections.

As a secondary line of defense, security practitioners should implement restrictive egress firewalls on application servers. A Next.js runtime rarely requires unrestricted network visibility over adjacent internal subnets, cloud metadata links, or peripheral utility APIs. Enforcing the principle of least privilege at the network layer significantly mitigates the blast radius of SSRF exploits, ensuring resilience even if analogous software defects surface in future iterations.

Concurrently, Netlify released a technical advisory confirming that its deployments are immune to this vector; Netlify Functions and Edge Functions do not natively support WebSocket protocol transitions, rendering the problematic logic dead code within their ecosystem. Cloudflare similarly counselled immediate package remediation, cautioning organizations against an over-reliance on Web Application Firewalls (WAF), as underlying design structures within React and Next.js can occasionally elude edge-based firewall rule definitions entirely.

Related coverage

  • ENDLESSDOORS: Hidden Remote Control Found in Zbtlink Router Firmware
  • iCloud Private Relay IP Leak: Three WebKit Flaws Expose Real User IP Addresses
  • AI Agents Go Rogue: Mythos 5 and GPT-5.6 Sol Escape Cyber Testbed, Target Real GitHub
  • Critical N-central Vulnerability Exploited in MSP Attacks
  • Google Password Manager Passkey Bypasses Uncovered

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Tags: Cloud Metadata ExploitCVE-2026-44578CWE-918Next.jsSecurity Patch 2026Self-Hosted Node.jsServer-Side Request ForgerySSRFVercelWebSocket Upgrade

Follow:

  • Next story Magecart Attack: Critical Flaw in FunnelKit Plugin Sparks Credit Card Skimming on 40,000+ WooCommerce Sites
  • Previous story Operation Masquerade: FBI Executes Remote Reset on Thousands of Routers to Purge Russian Malware

  • Recent Posts
  • Popular Posts
  • Tags
  • ENDLESSDOORS hidden backdoor in Zbtlink router firmware discovered by VulnCheck using rctl remote control Linux component masquerading as kernel threads with root access

    Vulnerability

    ENDLESSDOORS: Hidden Remote Control Found in Zbtlink Router Firmware

    August 7, 2026

  • iCloud Private Relay IP leak via three WebKit vulnerabilities DNS prefetch WebAuthn WebTransport bypassing proxy on iOS iPadOS macOS Safari and third-party browsers

    Vulnerability

    iCloud Private Relay IP Leak: Three WebKit Flaws Expose Real User IP Addresses

    August 7, 2026

  • Malware bypassing DNS security by connecting directly to C2 IP addresses Phorpiex SectopRAT Mozi botnet ZT-IP firewall detection Unit 42

    Malware

    45% of Malware C2 Traffic Bypasses DNS by Connecting Directly to IP Addresses

    August 7, 2026

  • Tactical police unit responding to coordinated swatting attacks with emergency vehicles

    Cyber Security

    FBI Warns of Coordinated Swatting Attacks Nationwide

    August 7, 2026

  • Tails 7.10.1 emergency patch for CVE-2026-64560 Linux kernel POSIX CPU timer race condition allowing Tor Browser privilege escalation and user deanonymization

    Linux

    Tails 7.10.1: Emergency Patch for CVE-2026-64560 That Could Deanonymize Users

    August 7, 2026

  • VMware vCenter vulnerability CVE-2026-59309 and CVE-2026-59310 rated CVSS 9.8 authentication bypass

    Vulnerability Report

    VMware vCenter CVE-2026-59309 and CVE-2026-59310 Rated CVSS 9.8

    July 29, 2026

  • OpenSUSE Leap 15.4 Beta releases, Linux distributions

    Linux

    OpenSUSE Leap 15.4 Beta releases, Linux distributions

    May 30, 2020

  • Ubuntu 16.04.6 LTS released: fix security vulnerabilities

    Linux

    Ubuntu 16.04.6 LTS released: fix security vulnerabilities

    March 1, 2019

  • GhostBSD 23.10.1 released, FreeBSD distribution

    Linux

    GhostBSD 23.10.1 released, FreeBSD distribution

    May 1, 2020

  • Solus 4.4 Fortitude releases, Linux distribution

    Linux

    Solus 4.4 Fortitude releases, Linux distribution

    January 26, 2020

  • AI AI security Android Apple APT BOTNET CISA cloud security Critical Infrastructure cryptocurrency cyberattack cybercrime Cyber Espionage cybersecurity Cybersecurity 2026 data breach Github google hacking Infosec InfoSec 2026 Infostealer Linux Linux Kernel malware Microsoft network security open source Penetration Testing phishing privacy privilege escalation Prompt Injection ransomware RCE remote code execution security Social Engineering supply chain attack Tech News 2026 threat intelligence vulnerability windows Windows 11 zero-day
  • Home
  • About Us
  • Contact Us
  • DMCA NOTICE
  • Privacy Policy

Information Security News © 2026. All Rights Reserved.

Powered by  - Designed with Hueman Pro