Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

vercel — Vulnerabilities & Security Advisories 68

Browse all 68 CVE security advisories affecting vercel. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Vercel operates as a cloud platform for frontend development, primarily hosting static sites and serverless functions. With thirty-five recorded Common Vulnerabilities and Exposures, the platform has historically faced issues ranging from Cross-Site Scripting (XSS) to Remote Code Execution (RCE). These vulnerabilities often stem from complex dependency chains or misconfigured serverless environments rather than fundamental architectural flaws. Notable incidents have included data exposure risks due to improper header configurations and potential privilege escalation through flawed API access controls. While the platform emphasizes rapid deployment, its reliance on third-party libraries and dynamic runtime environments introduces attack surfaces that require rigorous input validation and secure coding practices. Security audits frequently highlight the need for strict isolation between tenant environments to prevent cross-tenant data leakage, ensuring that the convenience of serverless architecture does not compromise overall system integrity.

CVE ID Title CVSS Severity Published
CVE-2026-44573 Next.js: Middleware / Proxy bypass in Pages Router applications using i18n — next.js CWE-863 7.5 High 2026-05-13
CVE-2026-44572 Next.js: Middleware / Proxy redirects can be cache-poisoned — next.js CWE-349 3.7 Low 2026-05-13
CVE-2026-44479 Vercel: Non-interactive mode includes CLI arguments in suggested command output — vercel CWE-200 5.5 Medium 2026-05-13
CVE-2026-29057 Next.js: HTTP request smuggling in rewrites — next.js CWE-444 9.1 - 2026-03-18
CVE-2026-27980 Next.js: Unbounded next/image disk cache growth can exhaust storage — next.js CWE-400 6.5 - 2026-03-18
CVE-2026-27979 Next.js: Unbounded postponed resume buffering can lead to DoS — next.js CWE-770 5.4 - 2026-03-18
CVE-2026-27978 Next.js: null origin can bypass Server Actions CSRF checks — next.js CWE-352 8.8 - 2026-03-17
CVE-2026-27977 Next.js: null origin can bypass dev HMR websocket CSRF checks — next.js CWE-1385 7.1 - 2026-03-17
CVE-2025-59471 Next.js 安全漏洞 — next 5.9 Medium 2026-01-26
CVE-2025-59472 Next.js 安全漏洞 — next 5.9 Medium 2026-01-26
CVE-2025-48985 AI SDK 安全漏洞 — AI SDK 3.7 Low 2025-11-07
CVE-2025-52662 Nuxt DevTools 安全漏洞 — Nuxt Devtools 6.9 Medium 2025-11-07
CVE-2025-57752 Next.js Affected by Cache Key Confusion for Image Optimization API Routes — next.js CWE-524 6.2 Medium 2025-08-29
CVE-2025-55173 Next.js Content Injection Vulnerability for Image Optimization — next.js CWE-20 4.3 Medium 2025-08-29
CVE-2025-57822 Next.js Improper Middleware Redirect Handling Leads to SSRF — next.js CWE-918 6.5 Medium 2025-08-29
CVE-2025-7074 vercel hyper rimraf-standalone.js ignoreMap redos — hyper CWE-1333 4.3 Medium 2025-07-05
CVE-2025-49826 Next.js DoS vulnerability via cache poisoning — next.js CWE-444 7.5 High 2025-07-03
CVE-2025-49005 Next.js cache poisoning due to omission of Vary header — next.js CWE-444 3.7 Low 2025-07-03
CVE-2025-48068 Information exposure in Next.js dev server due to lack of origin verification — next.js CWE-1385 2.5AI Low AI 2025-05-30
CVE-2025-32421 Next.js Race Condition to Cache Poisoning — next.js CWE-362 3.7 Low 2025-05-14
CVE-2025-46332 Information Disclosure via Flags override link — flags CWE-200 6.5 Medium 2025-05-02
CVE-2025-30218 Next.js may leak x-middleware-subrequest-id to external hosts — next.js CWE-200 7.5AI High AI 2025-04-02
CVE-2025-29927 Authorization Bypass in Next.js Middleware — next.js CWE-285 9.1 Critical 2025-03-21
CVE-2024-56332 Next.js Vulnerable to Denial of Service (DoS) with Server Actions — next.js CWE-770 5.3 Medium 2025-01-03
CVE-2024-51479 Authorization bypass in Next.js — next.js CWE-285 7.5 High 2024-12-17
CVE-2024-47831 Next.js image optimization has Denial of Service condition — next.js CWE-674 5.9 Medium 2024-10-14
CVE-2024-46982 Cache Poisoning in next.js — next.js CWE-639 7.5 High 2024-09-17
CVE-2024-39693 Next.js Denial of Service (DoS) condition — next.js CWE-400 7.5 High 2024-07-10
CVE-2024-34351 Next.js Server-Side Request Forgery in Server Actions — next.js CWE-918 7.5 High 2024-05-09
CVE-2024-34350 Next.js Vulnerable to HTTP Request Smuggling — next.js CWE-444 7.5 High 2024-05-09

This page lists every published CVE security advisory associated with vercel. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.