🚨 Next.js Vulnerability: CVE-2026-44578
→ affects self-hosted Next.js apps using the built-in Node.js server
→ impacts versions 13.4.13–15.5.15 and 16.0.0–16.2.4
→ attackers may expose internal services and cloud metadata endpoints through SSRF
→ around 79,000 exposed instances are reportedly vulnerable
Details: https://www.tenable.com/cve/CVE-2026-44578
Post #1296
185