SSRF
appsec.fyi
CCB Alert: Warning: Critical vulnerability in #Node.js server CVE-2026-44578 CVSS: 8.6. When using the built-in server server-side request forgery #SSRF is possible causing the server to proxy any requests to in- or external destinations. More info: #Patch #Patch
2026-05-18
Gray Hats: Critical SSRF vulnerability CVE-2026-44578 impacts self-hosted Next.js applications. Upgrade to version 15.5.16 or 16.2.5 immediately to block the exploit. #NextJS #SSRF #CVE202644578 #WebSecurity2026 #NodeJS #DevSecOps #AppSec
2026-05-18
CiberInteligencia Chile: NEXT.JS CRÍTICO: CVE-2026-44578 (SSRF) Falla en WebSocket robo de credenciales cloud API keys y acceso a paneles internos Afecta self-hosted. Actualiza para evitar explotación #Nextjs #SSRF #CVE #Ciberseguridad
2026-05-17
xHackInSeconds: URL field accepted internal addresses. 169.254.169.254. IAM role credentials in the response. Full S3 and RDS access. #infosec #cloud #ssrf
2026-05-17
White Rabbitx : CVE-2026-7221 A vulnerability in TencentCloudBase CloudBaseMCP up to 2.17.0 affects openUrl; manipulating req.body.url can lead to remote SSRF. #CVE-2026-7221 #CloudBaseMCP #SSRF #Vulnerability #CWE918 nvd.nist.gov/vuln/detail/CVE
2026-05-17
More SSRF →