
Nuclei templates for detecting CVE-2026-44578 (Next.js WebSocket Upgrade SSRF) with multi-cloud metadata validation, Next.js fingerprinting, and real-world scanning workflows. Includes references to the original NextSSRF research and exploit tooling.
Nuclei templates for detecting CVE-2026-44578 (Next.js WebSocket Upgrade SSRF) with multi-cloud metadata validation, Next.js fingerprinting, and real-world scanning workflows. Includes references to the original NextSSRF research and exploit tooling.
Nuclei templates for detecting CVE-2026-44578 — a Next.js WebSocket Upgrade Handler SSRF vulnerability affecting vulnerable self-hosted Next.js deployments.



Supported cloud providers:
The templates use malformed absolute-URI requests together with:
Connection: Upgrade
Upgrade: websocket
to trigger the vulnerable WebSocket upgrade handling logic in affected Next.js deployments.
The detection templates validate:
without extracting credentials or secrets.
Credits to the original researchers and tooling authors:
These templates are intended only for:
Only scan systems you own or have explicit permission to test.
This repository is provided for educational and authorized security testing purposes only.
The maintainers are not responsible for misuse, unauthorized scanning, or illegal activity performed using these templates.