<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet href="/rss.xsl" type="text/xsl"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>ModatMagnify | 笨蛋三月七的日常</title><description>互联网搬💩集散地BGP 分频: @bakanetwork内频：https://t.me/+KeNZttiOmFtlZjE1「愿你在未来与我的既往重逢」</description><link>https://broadcastchannel-95o.pages.dev</link><item><title>#碎碎念 #前端 #安全 #新动态看乐了，还好我已经远离 Next.js 了CVE-2026-44578 CVE-2026-44578 ⚠️ Next.js – WebSocket Upgrade SSRF (CVSS 8.6) A server-side request forgery vulnerability in Next.js allows unauthenticated attackers to force self-hosted instances to make internal HTTP requests via the WebSocket upgrade handler. By sending a crafted absolute-form HTTP request with Upgrade: websocket headers, attackers can access internal services, cloud metadata endpoints, admin panels, and internal APIs reachable from the Next.js server on port 80. Successful exploitation may expose cloud credentials, API keys, secrets, and configuration data. Affected: Next.js 13.4.13+, 14.x, 15.x &lt;15.5.16, 16.0.0–16.2.4 Mitigation: Upgrade immediately to 15.5.16 or 16.2.5.  Modat Magnify Query: technology=&quot;Next.js&quot; The platform: </title><link>https://broadcastchannel-95o.pages.dev/posts/2230</link><guid isPermaLink="true">https://broadcastchannel-95o.pages.dev/posts/2230</guid><pubDate>Thu, 14 May 2026 14:24:37 GMT</pubDate><content:encoded>&lt;div&gt;
      
        &lt;img src=&quot;https://cdn5.telesco.pe/file/J5wyT94ea9YyWIE2AjvteHEDK8p2CY7X6jJGj1TlpZvStmMR0EYYIfLlU6ouv8ThbAtE2T4Q5TvLdB1ZXG_2qG9Pm709aF4A5l5Ag-lx7TBUOjz4as8FVXPlNA5Ep4RUoUIoXKuII3yiQwVCeZJom9ihDUHC17px51a2Atn2lsYMC83uhayBvLn6iLUI0dUAT30t62eTW9otYt1zOkJLq02Rkv1BLrXmZYxeApWncMB0SfqRlGtnI8iE_lM26pZJxVqTvlxodJVxrBjsn_Pnf62w9y8I48VOqr-ReAPFwanAkK6ObuplHGhWpg_WUOkKw4vKTQnN07zu-JbfI2xdBg.jpg&quot; alt=&quot;#碎碎念 #前端 #安全 #新动态看乐了，还好我已经远离 Next.js 了CVE-2026-44578 CVE-2026-44578 ⚠️ Next.js – WebSocket Upgrade SSRF (CVSS 8.6) A server-side request forgery vulnerability in Next.js allows unauthenticated attackers to force self-hosted instances to make internal HTTP requests via the WebSocket upgrade handler. By sending a crafted absolute-form HTTP request with Upgrade: websocket headers, attackers can access internal services, cloud metadata endpoints, admin panels, and internal APIs reachable from the Next.js server on port 80. Successful exploitation may expose cloud credentials, API keys, secrets, and configuration data. Affected: Next.js 13.4.13+, 14.x, 15.x &amp;lt;15.5.16, 16.0.0–16.2.4 Mitigation: Upgrade immediately to 15.5.16 or 16.2.5.  Modat Magnify Query: technology=&quot; loading=&quot;lazy&quot; /&gt;
      
      
        
      
    &lt;/div&gt;&lt;a href=&quot;/search/%23%E7%A2%8E%E7%A2%8E%E5%BF%B5&quot;&gt;#碎碎念&lt;/a&gt; &lt;a href=&quot;/search/%23%E5%89%8D%E7%AB%AF&quot;&gt;#前端&lt;/a&gt; &lt;a href=&quot;/search/%23%E5%AE%89%E5%85%A8&quot;&gt;#安全&lt;/a&gt; &lt;a href=&quot;/search/%23%E6%96%B0%E5%8A%A8%E6%80%81&quot;&gt;#新动态&lt;/a&gt;&lt;br /&gt;看乐了，还好我已经远离 Next.js 了&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;https://x.com/modat_magnify/status/2054848379339837850&quot; target=&quot;_blank&quot;&gt;CVE-2026-44578 &lt;/a&gt;&lt;br /&gt;&lt;blockquote&gt;CVE-2026-44578 &lt;br /&gt;&lt;i&gt;&lt;b&gt;⚠️&lt;/b&gt;&lt;/i&gt; Next.js – WebSocket Upgrade SSRF (CVSS 8.6) &lt;br /&gt;&lt;br /&gt;A server-side request forgery vulnerability in Next.js allows unauthenticated attackers to force self-hosted instances to make internal HTTP requests via the WebSocket upgrade handler. &lt;br /&gt;By sending a crafted absolute-form HTTP request with Upgrade: websocket headers, attackers can access internal services, cloud metadata endpoints, admin panels, and internal APIs reachable from the Next.js server on port 80. Successful exploitation may expose cloud credentials, API keys, secrets, and configuration data. &lt;br /&gt;&lt;br /&gt;Affected: Next.js 13.4.13+, 14.x, 15.x &amp;lt;15.5.16, 16.0.0–16.2.4 &lt;br /&gt;&lt;br /&gt;Mitigation: Upgrade immediately to 15.5.16 or 16.2.5.  &lt;br /&gt;&lt;br /&gt;Modat Magnify Query: &lt;br /&gt;technology=&quot;Next.js&quot; &lt;br /&gt;&lt;br /&gt;The platform: &lt;br /&gt;&lt;a href=&quot;https://magnify.modat.io/&quot; target=&quot;_blank&quot;&gt;https://magnify.modat.io/&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;/search/%23threatintel&quot;&gt;#threatintel&lt;/a&gt; &lt;a href=&quot;/search/%23vulnerability&quot;&gt;#vulnerability&lt;/a&gt; &lt;a href=&quot;/search/%23CVE202644578&quot;&gt;#CVE202644578&lt;/a&gt; &lt;a href=&quot;/search/%23Nextjs&quot;&gt;#Nextjs&lt;/a&gt; &lt;a href=&quot;/search/%23SSRF&quot;&gt;#SSRF&lt;/a&gt; &lt;a href=&quot;/search/%23WebSocket&quot;&gt;#WebSocket&lt;/a&gt; &lt;a href=&quot;/search/%23CloudSecurity&quot;&gt;#CloudSecurity&lt;/a&gt; &lt;a href=&quot;/search/%23infosec&quot;&gt;#infosec&lt;/a&gt; &lt;a href=&quot;/search/%23Critical&quot;&gt;#Critical&lt;/a&gt; &lt;a href=&quot;/search/%23ModatMagnify&quot;&gt;#ModatMagnify&lt;/a&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;最近 CVE 好 热 闹 啊</content:encoded></item></channel></rss>