tag
Upgrade-Request
None assigned as of 2026-07-03
network
HIGH
nghttpx HTTP/1.1 Upgrade Request Body Response Queue Poisoning
nghttpx, the reverse proxy shipped with nghttp2, incorrectly accepts an HTTP/1.1 Upgrade request that also carries a Content-Length header, then forwards both the Upgrade headers and the body bytes unmodified to a keep-alive HTTP/1.1 backend connection. If…
Patched
2026-07-03
CVE-2026-44578
web
HIGH 8.6
EPSS 39%
Next.js WebSocket Upgrade SSRF (Self-Hosted) (CVE-2026-44578)
CVE-2026-44578 is a server-side request forgery (SSRF) vulnerability in self-hosted Next.js WebSocket upgrade handling. A crafted HTTP request with Upgrade: websocket can coerce vulnerable versions into proxying to attacker-chosen internal targets on port 80…
Patched
2026-05-17