logo

Critical Next.js Flaw Exposes Cloud Credentials, API Keys, and Admin Panels

ID: aec59452-c5ea-5cc5-9208-24ca385e0394

STIX ID: report--aec59452-c5ea-5cc5-9208-24ca385e0394

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2026-05-15

Date Updated: 2026-05-22

Author: AnuPriya

...
...

A high-severity SSRF vulnerability in self-hosted Next.js (CVE-2026-44578, CVSS 8.6) arises from improper validation of WebSocket upgrade requests, allowing unauthenticated attackers to forward requests to internal destinations such as cloud metadata endpoints and retrieve sensitive credentials; patched releases (15.5.16 and 16.2.5) are available and mitigations include avoiding direct exposure of origin servers, blocking WebSocket upgrades at proxies, and restricting outbound access to metadata services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.