Feed/CVE-2026-4457
CVE-2026-4457HIGHCVSS 8.8

CVE-2026-4457

Published Mar 19, 2026·Updated Jun 17, 2026

NVD Description

Type Confusion in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Public Exploits & PoCs7 found

[POC] CVE-2026-44578 — nextssrf

NextSSRF — CVE-2026-44578 Scanner & Exploit ║ ║ Next.js WebSocket Upgrade Handler SSRF

6

[POC] CVE-2026-44578 — CVE-2026-44578

CVE-2026-44578: Next.js WebSocket Upgrade SSRF — pre-auth credential theft via localhost:80. Lab + exploit + audit.

1

[POC] CVE-2026-44578 — next-16.2.4-pocs

Next.js v16.2.4 Security PoC Collection (CVE-2026-44578, CVE-2026-44574, CVE-2026-23870, GHSA-267c-6grr-h53f, GHSA-mg66-mrh9-m8jx, CVE-2026-44573, GHSA-gx5p-jg67-6x7h, GHSA-h64f-5h5j-jqjh, GHSA-wfc6-r584-vfw7, CVE-2026-44581, CVE-2026-44582, GHSA-3g8h-86w9-wvmq)

1

[POC] CVE-2026-44578 — verify-ghsa-c4j6-fc7j-m34r

OOB verifier for GHSA-c4j6-fc7j-m34r / CVE-2026-44578 (Next.js WebSocket-upgrade SSRF)

[POC] CVE-2026-44578 — nextjs-cve-2026-44578

Nuclei templates for detecting CVE-2026-44578 (Next.js WebSocket Upgrade SSRF) with multi-cloud metadata validation, Next.js fingerprinting, and real-world scanning workflows. Includes references to the original NextSSRF research and exploit tooling.

[POC] CVE-2026-44578 — CVE-2026-44578

CVE-2026-44578

[POC] CVE-2026-44578 — NEXT-SSRF

SSRF — CVE-2026-44578 Scanner & Exploit ║ ║ Next.js WebSocket Upgrade Handler SSRF

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free