Security Research

CVE-2024-34351 Next.js SSRF: Server Actions and the Host Header's Quiet Collusion

#Vulnerability Analysis#Code Audit#Web Security
Dark dossier of Next.js Server Actions and SSRF path

Next.js’ Server Actions trust the user-controlled Host header during a redirect flow. An apparently innocent internal fetch exposes internal HTTP services to any external attacker — and a Flask pivot upgrades the SSRF from a ping to a full read.

Unlock to view this content.