Server-side request forgery (SSRF) In next
Description
A flaw was found in Next.js. Self-hosted applications utilizing the built-in Node.js server are vulnerable to Server-Side Request Forgery (SSRF) through specially crafted WebSocket upgrade requests. A remote attacker can exploit this by causing the server to proxy requests to arbitrary internal or external destinations. This could lead to the exposure of internal services or sensitive cloud metadata endpoints.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
npm | 15.5.16, 16.2.5 | ||
rpm rhel8 | - | - | |
rpm rhel8 | - | - | |
rpm rhel9 | - | - | |
rpm rhel10 | - | - | |
rpm rhel9 | - | - | |
rpm rhel10 | - | - | |
rpm rhel7 | - | - |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4. 5.