MIRAGE
Threat IntelligenceCVEs › CVE-2026-44578

CVE-2026-44578 — exposed on the internet

CVE-2026-44578: CWE-918: Server-Side Request Forgery (SSRF) in vercel next.js

Internet exposure observed by OffSeq scans · last 30 days

1
Exposed hosts
8.6
CVSS
38.9%
EPSS

Found on 1 internet-exposed hosts by OffSeq scans; no in-the-wild exploitation has been observed against OffSeq honeypots in this window.

About CVE-2026-44578

Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed in 15.5.16 and 16.2.5.

Vendor: vercelCWE-918

OffSeq internet scanning found CVE-2026-44578 on 1 exposed hosts in the last 30 days. OffSeq honeypots have not recorded in-the-wild exploitation of this CVE in the current window — this page tracks its exposure footprint and status; if exploitation begins, the live honeypot signal will appear here.

Exposed-host countries

Exposed via

grafana

Open the live CVE-2026-44578 view →

References