Vendor
Vercel vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 86 vulnerabilities in Vercel: 0 in the last 7 days and 15 in the last 90 days, 4 of them critical and 1 exploited in the wild. The most recent, Next.js heap buffer overflow in image optimization via malicious AVIF, was published on 8 September 2026. 3 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 15
- Critical, all time
- 4
- Exploited in the wild
- 1
About Vercel
Cloud platform for deploying and hosting web applications and serverless functions.
Vercel technologies
Latest Vercel vulnerabilities
- Next.js heap buffer overflow in image optimization via malicious AVIFcriticalCVSS 9.5
- Next.js Image Optimization heap buffer overflow via AVIFmediumCVSS 4
- CVE-2026-75604: Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js…criticalCVSS 9EPSS 2.3%
- Next.js and libheif RCE in HEIF/AVIF image processinginfoCVSS 9.8
- CVE-2026-64649: Vercel Next.js SSRF in Server Actions on custom servershighCVSS 4EPSS 0.5%
- CVE-2026-64648: Vercel Next.js cache confusion in server-side fetchmediumCVSS 4EPSS 0.3%
- CVE-2026-64647: Vercel Next.js cache confusion in server-side fetch requestsmediumCVSS 4EPSS 0.3%
- CVE-2026-64646: Vercel Next.js denial of service in Server Actions Edge runtimemediumCVSS 4EPSS 0.5%
- CVE-2026-64645: Vercel Next.js SSRF and Open Redirect in rewrites and redirectshighCVSS 4EPSS 0.4%
- CVE-2026-64644: Vercel Next.js denial of service in Image Optimization APImediumCVSS 4EPSS 0.7%
- CVE-2026-64643: Vercel Next.js authentication bypass in Server Function endpointsmediumCVSS 4EPSS 0.5%
- CVE-2026-64642: Vercel Next.js authentication bypass in Turbopack middleware matcherhighCVSS 4EPSS 0.6%
- CVE-2026-64641: Vercel Next.js denial of service in App Router Server ActionshighCVSS 4EPSS 0.9%
- CVE-2026-64651: Vercel AI SDK authorization bypass in OpenCode harness tool relayinfoCVSS 6.3
- CVE-2026-64650: Vercel AI SDK Codex harness authorization bypass in tool relayinfoCVSS 6.3
- CVE-2026-8769: Vercel AI SDK denial of service in provider-utils response handlermediumCVSS 4.3EPSS 0.7%
- CVE-2026-8768: Vercel AI SSRF via HTTP redirect in provider-utilshighCVSS 7.3
- CVE-2026-8767: Vercel AI OS command injection in GitHub Actions workflowmediumCVSS 5
- CVE-2026-46508: Vercel Turborepo command injection in VS Code extensioninfoCVSS 8.4EPSS 0.0%
- CVE-2026-45773: Vercel Turborepo CSRF and session fixation in self-hosted login flowmediumCVSS 4EPSS 0.2%
- CVE-2026-45772: Vercel Turborepo arbitrary code execution via malicious Yarn configurationcriticalCVSS 9.8EPSS 0.6%
- CVE-2026-45109: Vercel Next.js authentication bypass in middleware with TurbopackhighCVSS 7.5EPSS 0.8%
- CVE-2026-44582: Vercel Next.js cache poisoning in React Server ComponentslowCVSS 3.7EPSS 0.2%
- CVE-2026-44581: Vercel Next.js stored XSS in App Router via CSP nonce reflectionmediumCVSS 4.7EPSS 0.3%
- CVE-2026-44580: Vercel Next.js cross-site scripting in beforeInteractive scriptsmediumCVSS 6.1EPSS 0.3%
Most severe Vercel vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-55182: A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0…criticalexploited in the wildCVSS 10EPSS 99.8%
- CVE-2026-45772: Vercel Turborepo arbitrary code execution via malicious Yarn configurationcriticalCVSS 9.8EPSS 0.6%
- Next.js heap buffer overflow in image optimization via malicious AVIFcriticalCVSS 9.5
- CVE-2026-75604: Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js…criticalCVSS 9EPSS 2.3%
- CVE-2026-44578: Vercel Next.js SSRF via WebSocket upgrade requestshighCVSS 8.6EPSS 1.9%
- CVE-2026-44574: Vercel Next.js authorization bypass in dynamic route middlewarehighCVSS 8.1EPSS 0.7%
- CVE-2026-23870: Facebook React Denial of Service in React Server ComponentshighCVSS 7.5EPSS 1.5%
- CVE-2026-45109: Vercel Next.js authentication bypass in middleware with TurbopackhighCVSS 7.5EPSS 0.8%
- CVE-2026-44579: Vercel Next.js connection exhaustion in Cache ComponentshighCVSS 7.5EPSS 0.8%
- CVE-2026-44575: Vercel Next.js auth bypass in App Router middlewarehighCVSS 7.5EPSS 0.8%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 2 | 0 | |
| 27 Jul 2026 | 9 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 1 | 0 | |
| 31 Aug 2026 | 1 | 1 | |
| 7 Sep 2026 | 2 | 1 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/vercel.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Vercel vulnerabilities", https://junglewise.ai/threats/vendors/vercel, 26 September 2026.