CVE-2024-34351 is a server-side request forgery vulnerability in Next.js Server Actions affecting self-hosted Next.js deployments from version 13.4 through versions before 14.1.1. When a Server Action redirects to a relative path beginning with a slash, vulnerable redirect handling constructs a server-side request using the client-supplied HTTP Host header as the destination host. An attacker able to invoke the action with a modified Host header can cause the Next.js server to request an attacker-selected destination. The request flow initially issues a HEAD request; an attacker-controlled endpoint can return a React Server Components content type and redirect the subsequent GET request to an internal target, enabling response-reading SSRF.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository is a compact, working demonstration of CVE-2024-34351, an SSRF issue in Next.js Server Actions affecting vulnerable versions such as next@14.0.0 and fixed in 14.1.1. The exploit path is intentionally minimal: page.tsx renders a login form whose submission invokes the server action in actions.ts; that action unconditionally calls redirect('/dashboard'). In vulnerable Next.js builds, this redirect causes the framework to construct an internal fetch URL using the attacker-controlled Host header from the incoming request, enabling SSRF to arbitrary destinations reachable by the server. Repository structure is straightforward: README.md explains the bug, setup, and exploitation workflow; actions.ts contains the vulnerable trigger; page.tsx provides the form that generates the POST request; dashboard_page.tsx is the nominal redirect destination; layout.tsx, next.config.js, package.json, and tsconfig.json provide standard Next.js app scaffolding; attack_server.py is a helper server for exploitation. The Python helper is operational exploit support code rather than mere documentation: it listens on a configurable port, logs inbound SSRF requests, answers HEAD with Content-Type: text/x-component to satisfy Next.js gating logic, and then serves a GET response body that will be reflected back through the vulnerable application. Main exploit capabilities: (1) trigger server-side outbound HEAD requests to attacker-controlled infrastructure by modifying the Host header; (2) escalate from simple SSRF confirmation to full response-body retrieval using the included attacker server; and (3) target internal services such as AWS EC2 metadata at 169.254.169.254, including IAM credential paths. This is not a framework module and not just a detector; it is a runnable demo exploit environment plus a helper capture server. Overall maturity is operational: the payload is basic and hardcoded, but the repository provides all components needed to reproduce and observe the SSRF behavior.
This repository provides a proof-of-concept (PoC) exploit for CVE-2024-34351, a server-side request forgery (SSRF) vulnerability in Next.js (prior to version 14.1.1). The exploit consists of two redirect server implementations: one in Python (attacker-server.py) and one in TypeScript for Deno (attacker-server.ts). These servers listen for incoming HTTP requests, log the request details, and issue a 302 redirect to a URL specified in the 'SSRF' header. The README explains how to use these servers in conjunction with a vulnerable Next.js instance by manipulating the Host, Origin, and SSRF headers to trigger SSRF and retrieve arbitrary web content via the Next.js server. The repository is structured simply, with a README and two code files, and is intended for demonstration and testing of the SSRF vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A server-side request forgery vulnerability in Next.js Server Actions. By manipulating the Host header under the stated conditions, an attacker can cause the application server to make arbitrary requests and read their complete responses, potentially reaching internal-network services or cloud metadata IPs for privilege escalation.
A Next.js Server Actions SSRF vulnerability caused by constructing an internal redirect-fetch URL from an attacker-controlled Host header. It could be escalated from blind SSRF to full response disclosure by satisfying the HEAD-request content-type check and redirecting the subsequent GET request to an internal target.
Specific vulnerability identified as CVE-2024-34351, discussed in the context of updating a detection template and addressing false-positive detection behavior.
A server-side request forgery vulnerability in Next.js Server Actions.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.