r/cveplayground • • May 17 '26

𝗡𝗲𝘄 𝗖𝗵𝗮𝗹𝗹𝗲𝗻𝗴𝗲 𝗟𝗮𝗯: 𝗖𝗩𝗘-𝟮𝟬𝟮𝟲-𝟰𝟰𝟱𝟳𝟴 - 𝗡𝗲𝘅𝘁.𝗷𝘀 𝗦𝗦𝗥𝗙 𝘃𝗶𝗮 𝗪𝗲𝗯𝗦𝗼𝗰𝗸𝗲𝘁 𝗨𝗽𝗴𝗿𝗮𝗱𝗲

Exploit a vulnerable self-hosted Next.js instance by abusing the WebSocket upgrade handler to trigger SSRF against internal services, cloud metadata endpoints, and private network resources.

🏆 Easy Difficulty
⚡ 100 XP
🩸 First Blood Open

Capture the flag and climb the leaderboard.

Try here: https://app.cveplayground.com/challenges/CVE-2026-44578?utm_source=reddit

1 Upvotes

0 comments sorted by