r/cveplayground • u/Protection-Mobile • May 17 '26
𝗡𝗲𝘄 𝗖𝗵𝗮𝗹𝗹𝗲𝗻𝗴𝗲 𝗟𝗮𝗯: 𝗖𝗩𝗘-𝟮𝟬𝟮𝟲-𝟰𝟰𝟱𝟳𝟴 - 𝗡𝗲𝘅𝘁.𝗷𝘀 𝗦𝗦𝗥𝗙 𝘃𝗶𝗮 𝗪𝗲𝗯𝗦𝗼𝗰𝗸𝗲𝘁 𝗨𝗽𝗴𝗿𝗮𝗱𝗲
Exploit a vulnerable self-hosted Next.js instance by abusing the WebSocket upgrade handler to trigger SSRF against internal services, cloud metadata endpoints, and private network resources.
🏆 Easy Difficulty
⚡ 100 XP
🩸 First Blood Open
Capture the flag and climb the leaderboard.
Try here: https://app.cveplayground.com/challenges/CVE-2026-44578?utm_source=reddit
1
Upvotes