FixVibe

// code / spotlight

Next.js WebSocket SSRF Dependency Advisory

Affected self-hosted Next.js servers need a framework upgrade.

What it is

The upstream advisory applies to self-hosted applications using the built-in Next.js Node.js server. Vercel-hosted deployments are not affected, so this one matters when you run Next.js yourself on a VPS, a container platform, or any host that runs the Node.js server directly.

How it happens

CVE-2026-44578 is a server-side request forgery in how the built-in Next.js server handles WebSocket upgrade requests. A crafted upgrade request can make the server open a connection to a destination the attacker chooses. It is fixed in Next.js 15.5.16 on the 13.x to 15.x line and 16.2.5 on the 16.x line.

What an attacker gets

Under the advisory's self-hosting and routing conditions, crafted WebSocket upgrade handling can cause the server to proxy requests to unintended internal or external destinations. Practical exposure depends on the deployed server mode, origin reachability, routing configuration, outbound network policy, and destination reachability.

// what fixvibe reports

What FixVibe reports

Runs when you connect a GitHub repository, on Pro and above. Each finding shows the file and line, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Upgrade to Next.js 15.5.16 or newer on the 13.x-15.x line, or 16.2.5 or newer on the 16.x line. Regenerate the active lockfile and rebuild self-hosted server artifacts. For self-hosted origins, review external rewrites, WebSocket handling, origin exposure, network segmentation, and egress controls; block unneeded WebSocket upgrades while rollout completes.

// lass es auf deiner eigenen App laufen

Ship weiter, während FixVibe mitwacht.

Connect a GitHub repo to check its code, dependencies and workflows.

Quellcode
198
Tests in dieser Kategorie
Module
155
dedizierte quellcode-Prüfungen
GitHub repos
190+
checks on each connected repo
Connect GitHub →

// aktuelle Checks · praktische Fixes · mit Vertrauen shippen

Next.js WebSocket SSRF Dependency Advisory: what it is and how to fix it · FixVibe