vciy

CVEs we hold for Vercel

Records whose assigning authority named Vercel as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-8769vercel ai provider-utils response-handler.ts createJsonErrorResponseHandler resource consumptionvercel ai
CVE-2026-8768vercel ai provider-utils download-blob.ts validateDownloadUrl server-side request forgeryvercel ai
CVE-2026-8767vercel ai PR Branch Name Interpolation prettier-on-automerge.yml run os command injectionvercel ai
CVE-2026-75604Next.js: Unauthenticated Remote Code Execution on windows-hosted serversvercel next.js
CVE-2026-64651AI SDK OpenCode Harness Tool Relay Authorization Bypassvercel @ai-sdk/harness-opencode
CVE-2026-64650AI SDK Codex Harness Tool Relay Authorization Bypassvercel @ai-sdk/harness-codex
CVE-2026-64649Next.js: Server-Side Request Forgery in Server Actions on Custom Serversvercel next.js
CVE-2026-64648Next.js: Response Body Cache Confusion for Requests Containing Bodiesvercel next.js
CVE-2026-64647Next.js: Response Body Cache Confusion with Invalid UTF-8 Request Bodiesvercel next.js
CVE-2026-64646Next.js: Unbounded Server Action payload in Edge runtimevercel next.js
CVE-2026-64645Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostnamevercel next.js
CVE-2026-64644Next.js: Denial of Service in the Image Optimization API using SVGsvercel next.js
CVE-2026-64643Next.js: Unauthenticated Disclosure of Internal Server Function endpointsvercel next.js
CVE-2026-64642Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single localevercel next.js
CVE-2026-64641Next.js: Denial of Service in App Router using Server Actionsvercel next.js
CVE-2026-46508Turborepo: VSCode Extension command injectionvercel turborepo
CVE-2026-45773Turborepo: Login callback CSRF/session fixationvercel turborepo
CVE-2026-45772Turborepo: Unexpected local code execution during Yarn Berry detectionvercel turborepo; @turbo codemod; @turbo workspaces
CVE-2026-45109Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routesvercel next.js
CVE-2026-44582Next.js: Cache poisoning via collisions in React Server Component cache-bustingvercel next.js
CVE-2026-44581Next.js: Cross-site scripting in App Router applications using CSP noncesvercel next.js
CVE-2026-44580Next.js: Cross-site scripting in beforeInteractive scripts with untrusted inputvercel next.js
CVE-2026-44579Next.js: Denial of Service via connection exhaustion in applications using Cache Componentsvercel next.js
CVE-2026-44578Next.js: Server-side request forgery in applications using WebSocket upgradesvercel next.js
CVE-2026-44577Next.js: Denial of Service in the Image Optimization APIvercel next.js
CVE-2026-44576Next.js: Cache poisoning in React Server Component responsesvercel next.js
CVE-2026-44575Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routesvercel next.js
CVE-2026-44574Next.js: Middleware / Proxy bypass through dynamic route parameter injectionvercel next.js
CVE-2026-44573Next.js: Middleware / Proxy bypass in Pages Router applications using i18nvercel next.js
CVE-2026-44572Next.js: Middleware / Proxy redirects can be cache-poisonedvercel next.js
CVE-2026-44479Vercel: Non-interactive mode includes CLI arguments in suggested command outputvercel
CVE-2026-29057Next.js: HTTP request smuggling in rewritesvercel next.js
CVE-2026-27980Next.js: Unbounded next/image disk cache growth can exhaust storagevercel next.js
CVE-2026-27979Next.js: Unbounded postponed resume buffering can lead to DoSvercel next.js
CVE-2026-27978Next.js: null origin can bypass Server Actions CSRF checksvercel next.js
CVE-2026-27977Next.js: null origin can bypass dev HMR websocket CSRF checksvercel next.js
CVE-2025-7074vercel hyper rimraf-standalone.js ignoreMap redosvercel hyper
CVE-2025-59472no title heldvercel next
CVE-2025-59471no title heldvercel next
CVE-2025-57822Next.js Improper Middleware Redirect Handling Leads to SSRFvercel next.js
CVE-2025-57752Next.js Affected by Cache Key Confusion for Image Optimization API Routesvercel next.js
CVE-2025-55173Next.js Content Injection Vulnerability for Image Optimizationvercel next.js
CVE-2025-52662no title heldVercel Nuxt Devtools
CVE-2025-49826Next.js DoS vulnerability via cache poisoningvercel next.js
CVE-2025-49005Next.js cache poisoning due to omission of Vary headervercel next.js
CVE-2025-48985no title heldVercel AI SDK
CVE-2025-48068Information exposure in Next.js dev server due to lack of origin verificationvercel next.js
CVE-2025-46332Information Disclosure via Flags override linkvercel flags
CVE-2025-32421Next.js Race Condition to Cache Poisoningvercel next.js
CVE-2025-30218Next.js may leak x-middleware-subrequest-id to external hostsvercel next.js
CVE-2025-29927Authorization Bypass in Next.js Middlewarevercel next.js
CVE-2024-56332Next.js Vulnerable to Denial of Service (DoS) with Server Actionsvercel next.js
CVE-2024-51479Authorization bypass in Next.jsvercel next.js
CVE-2024-47831Next.js image optimization has Denial of Service conditionvercel next.js
CVE-2024-46982Cache Poisoning in next.jsvercel next.js
CVE-2024-39693Next.js Denial of Service (DoS) conditionvercel next.js
CVE-2024-34351Next.js Server-Side Request Forgery in Server Actionsvercel next.js
CVE-2024-34350Next.js Vulnerable to HTTP Request Smugglingvercel next.js
CVE-2024-24828Local Privilege Escalation in execuatables bundled by pkgvercel pkg
CVE-2022-36046Unexpected server crash in Next.js version 12.2.3vercel next.js
CVE-2022-23646Improper CSP in Image Optimization API for Next.jsvercel next.js
CVE-2021-43803Unexpected server crash in Next.jsvercel next.js
CVE-2021-39178XSS in Image Optimization API for Next.js versions between 10.0.0 and 11.1.0vercel next.js
CVE-2021-37699Open Redirect in Next.js versions below 11.1.0vercel next.js
CVE-2020-15242Open Redirect in Next.jsvercel next.js
CVE-2017-20162vercel ms index.js parse redosvercel ms

66 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.