CVEs we hold for Vercel
Records whose assigning authority named Vercel as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-8769vercel ai provider-utils response-handler.ts createJsonErrorResponseHandler resource consumptionvercel ai
CVE-2026-8768vercel ai provider-utils download-blob.ts validateDownloadUrl server-side request forgeryvercel ai
CVE-2026-8767vercel ai PR Branch Name Interpolation prettier-on-automerge.yml run os command injectionvercel ai
CVE-2026-75604Next.js: Unauthenticated Remote Code Execution on windows-hosted serversvercel next.js
CVE-2026-64651AI SDK OpenCode Harness Tool Relay Authorization Bypassvercel @ai-sdk/harness-opencode
CVE-2026-64649Next.js: Server-Side Request Forgery in Server Actions on Custom Serversvercel next.js
CVE-2026-64647Next.js: Response Body Cache Confusion with Invalid UTF-8 Request Bodiesvercel next.js
CVE-2026-64645Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostnamevercel next.js
CVE-2026-64643Next.js: Unauthenticated Disclosure of Internal Server Function endpointsvercel next.js
CVE-2026-64642Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single localevercel next.js
CVE-2026-45772Turborepo: Unexpected local code execution during Yarn Berry detectionvercel turborepo; @turbo codemod; @turbo workspaces
CVE-2026-45109Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routesvercel next.js
CVE-2026-44582Next.js: Cache poisoning via collisions in React Server Component cache-bustingvercel next.js
CVE-2026-44581Next.js: Cross-site scripting in App Router applications using CSP noncesvercel next.js
CVE-2026-44580Next.js: Cross-site scripting in beforeInteractive scripts with untrusted inputvercel next.js
CVE-2026-44579Next.js: Denial of Service via connection exhaustion in applications using Cache Componentsvercel next.js
CVE-2026-44578Next.js: Server-side request forgery in applications using WebSocket upgradesvercel next.js
CVE-2026-44575Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routesvercel next.js
CVE-2026-44574Next.js: Middleware / Proxy bypass through dynamic route parameter injectionvercel next.js
CVE-2026-44573Next.js: Middleware / Proxy bypass in Pages Router applications using i18nvercel next.js
CVE-2025-57752Next.js Affected by Cache Key Confusion for Image Optimization API Routesvercel next.js
CVE-2025-48068Information exposure in Next.js dev server due to lack of origin verificationvercel next.js
CVE-2021-39178XSS in Image Optimization API for Next.js versions between 10.0.0 and 11.1.0vercel next.js
66 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.