What it is
The upstream advisory applies to self-hosted applications using the built-in Next.js Node.js server. Vercel-hosted deployments are not affected, so this one matters when you run Next.js yourself on a VPS, a container platform, or any host that runs the Node.js server directly.
How it happens
CVE-2026-44578 is a server-side request forgery in how the built-in Next.js server handles WebSocket upgrade requests. A crafted upgrade request can make the server open a connection to a destination the attacker chooses. It is fixed in Next.js 15.5.16 on the 13.x to 15.x line and 16.2.5 on the 16.x line.
What an attacker gets
Under the advisory's self-hosting and routing conditions, crafted WebSocket upgrade handling can cause the server to proxy requests to unintended internal or external destinations. Practical exposure depends on the deployed server mode, origin reachability, routing configuration, outbound network policy, and destination reachability.
// what fixvibe reports
What FixVibe reports
Runs when you connect a GitHub repository, on Pro and above. Each finding shows the file and line, its severity and fix steps you can paste into your AI coding tool.
How to fix it
Upgrade to Next.js 15.5.16 or newer on the 13.x-15.x line, or 16.2.5 or newer on the 16.x line. Regenerate the active lockfile and rebuild self-hosted server artifacts. For self-hosted origins, review external rewrites, WebSocket handling, origin exposure, network segmentation, and egress controls; block unneeded WebSocket upgrades while rollout completes.
