Web Hack List

Collected research

Digging for SSRF in NextJS apps

Examines Next.js server actions and redirect handling to turn attacker-controlled Host headers and application redirects into server-side requests. The technique can make a vulnerable deployment fetch internal or external resources and return response data.

Record

Researcher
Shubham Shah
Published by
slcyber.io

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Shubham Shah, first published at the original source. Preserved copies are kept so the citation survives its host.