Bug 2477187 (CVE-2026-44578) - CVE-2026-44578 Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests
Summary: CVE-2026-44578 Next.js: Next.js: Server-Side Request Forgery via crafted WebS...
Keywords:
Status: NEW
Alias: CVE-2026-44578
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2484253 2484266 2484268 2484251 2484269 2484270 2484271
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-13 18:01 UTC by OSIDB Bzimport
Modified: 2026-07-02 00:05 UTC (History)
16 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:34608 0 None None None 2026-07-02 00:05:02 UTC

Description OSIDB Bzimport 2026-05-13 18:01:36 UTC
Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed in 15.5.16 and 16.2.5.

Comment 2 errata-xmlrpc 2026-07-02 00:05:00 UTC
This issue has been addressed in the following products:

  Streams for Apache Kafka 2.9.4

Via RHSA-2026:34608 https://access.redhat.com/errata/RHSA-2026:34608


Note You need to log in before you can comment on or make changes to this bug.