vercel
Latest CVEs
The 15 most recently published vulnerabilities affecting vercel.
- CVE-2026-64649Next.js: Server-Side Request Forgery in Server Actions on Custom Servers6.5
- CVE-2026-64648Next.js: Response Body Cache Confusion for Requests Containing Bodies5.4
- CVE-2026-64647Next.js: Response Body Cache Confusion with Invalid UTF-8 Request Bodies5.4
- CVE-2026-64646Next.js: Unbounded Server Action payload in Edge runtime5.3
- CVE-2026-64644Next.js: Denial of Service in the Image Optimization API using SVGs5.3
- CVE-2026-64643Next.js: Unauthenticated Disclosure of Internal Server Function endpoints5.3
- CVE-2026-64642Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale8.2
- CVE-2026-64641Next.js: Denial of Service in App Router using Server Actions7.5
- CVE-2026-64645Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname6.1
- CVE-2026-8769vercel ai provider-utils response-handler.ts createJsonErrorResponseHandler resource consumption4.3
- CVE-2026-8768vercel ai provider-utils download-blob.ts validateDownloadUrl server-side request forgery7.3
- CVE-2026-8767vercel ai PR Branch Name Interpolation prettier-on-automerge.yml run os command injection5.0
- CVE-2026-45773Turborepo: Login callback CSRF/session fixation6.5
- CVE-2026-46508Turborepo: VSCode Extension command injection7.8
- CVE-2026-45772Turborepo: Unexpected local code execution during Yarn Berry detection9.8