PoC Archive PoC Archive

tag

Upgrade-Request

  • None assigned as of 2026-07-03 network HIGH

    nghttpx HTTP/1.1 Upgrade Request Body Response Queue Poisoning

    nghttpx, the reverse proxy shipped with nghttp2, incorrectly accepts an HTTP/1.1 Upgrade request that also carries a Content-Length header, then forwards both the Upgrade headers and the body bytes unmodified to a keep-alive HTTP/1.1 backend connection. If…

    Patched 2026-07-03
  • CVE-2026-44578 web HIGH 8.6 EPSS 39%

    Next.js WebSocket Upgrade SSRF (Self-Hosted) (CVE-2026-44578)

    CVE-2026-44578 is a server-side request forgery (SSRF) vulnerability in self-hosted Next.js WebSocket upgrade handling. A crafted HTTP request with Upgrade: websocket can coerce vulnerable versions into proxying to attacker-chosen internal targets on port 80…

    Patched 2026-05-17