



Vector 🥷⚡️
14.1K posts

@judeVector
backend engineer | distributed systems | building @sendryxhq | rust 🦀, python, typescript | contributor @superteamng | svm @solanaturbine | alumni @alx_africa





CVE-2026-44578 ⚠️ Next.js – WebSocket Upgrade SSRF (CVSS 8.6) A server-side request forgery vulnerability in Next.js allows unauthenticated attackers to force self-hosted instances to make internal HTTP requests via the WebSocket upgrade handler. By sending a crafted absolute-form HTTP request with Upgrade: websocket headers, attackers can access internal services, cloud metadata endpoints, admin panels, and internal APIs reachable from the Next.js server on port 80. Successful exploitation may expose cloud credentials, API keys, secrets, and configuration data. Affected: Next.js 13.4.13+, 14.x, 15.x <15.5.16, 16.0.0–16.2.4 Mitigation: Upgrade immediately to 15.5.16 or 16.2.5. Modat Magnify Query: technology="Next.js" The platform: magnify.modat.io #threatintel #vulnerability #CVE202644578 #Nextjs #SSRF #WebSocket #CloudSecurity #infosec #Critical #ModatMagnify



JUST IN: GitLab announces job cuts to reinvest in growth for the “agentic era.”

Nobel Prize physicist Frank Wilczek says matter, energy, and even reality itself may ultimately emerge from information.


Unmarried and pregnant in the UK. Listen. 🇬🇧👇



@EOEboh What about rust?🌚



🚨 BREAKING: 84 TanStack npm packages were compromised in an ongoing Mini Shai-Hulud supply chain attack, adding suspected CI credential-stealing malware. Socket flagged every malicious version within six minutes of publication. This is a developing story.


@jayhemz This is an erp system I built : stafferp.ethsch.org, This is a social app that was done with laravel, alpinejs , it has a flutter mobile app too: protagram.org And others I can't put up here, sir(NDA).






