Next.js 13.4.13 to before 15.5.16 and 16.2.5 contains a server-side request forgery caused by crafted WebSocket upgrade requests in the built-in Node.js server, letting attackers proxy requests to arbitrary destinations, exploit requires self-hosted deployment.
id: CVE-2026-44578
info:
name: Next.js WebSocket Upgrade Handler - SSRF
author: hacktron,Dhiyan
...