Junglewise Threat Intelligence

CVE-2026-44578: Vercel Next.js SSRF via WebSocket upgrade requests

CVE-2026-44578 · Severity: high · CVSS 8.6 · Published 2026-05-13

Technologies: Vercel Next.js. Vendors: Vercel.

Executive brief

Next.js is a popular framework used to build and host web applications. A security flaw in its built-in server allows attackers to trick the application into making unauthorized requests to internal systems or cloud management services. This could lead to the exposure of sensitive internal data or administrative credentials, though applications hosted directly on the Vercel platform are not affected.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Next.js when using the built-in Node.js server for self-hosting. The flaw is located in the handling of WebSocket upgrade requests, which fail to undergo the same safety checks applied to standard HTTP requests. A remote, unauthenticated attacker can send a specially crafted upgrade request to force the server to proxy traffic to arbitrary internal or external destinations. This can be used to bypass network segmentation and access internal services or cloud metadata endpoints (e.g., IMDS). The issue is fixed in versions 15.5.16 and 16.2.5.

Affected products

  • Vercel Next.js >= 13.4.13, < 15.5.16; >= 16.0.0, < 16.2.5

Timeline

  • 2026-05-06: advisory: GitHub advisory published by Vercel
  • 2026-05-13: disclosed: CVE published to NVD

References

Related threats