{"schema_version":1,"title":"Vercel vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 86 vulnerabilities in Vercel: 0 in the last 7 days and 15 in the last 90 days, 4 of them critical and 1 exploited in the wild. The most recent, Next.js heap buffer overflow in image optimization via malicious AVIF, was published on 8 September 2026. 3 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/vercel","json_url":"https://junglewise.ai/threats/vendors/vercel.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/vercel","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":16,"all_time":86,"critical":4,"exploited":1,"last_7_days":0,"last_30_days":3,"last_90_days":15,"last_365_days":55},"latest":[{"cvss":9.5,"slug":"next-js-heap-buffer-overflow-in-image-optimization-via-malicious-avif-90b951e0","title":"Next.js heap buffer overflow in image optimization via malicious AVIF","severity":"critical","exploited":false,"published_at":"2026-09-08T21:21:12+00:00","url":"https://junglewise.ai/threats/next-js-heap-buffer-overflow-in-image-optimization-via-malicious-avif-90b951e0"},{"cvss":4,"slug":"next-js-image-optimization-heap-buffer-overflow-via-avif-9ce530ed","title":"Next.js Image Optimization heap buffer overflow via AVIF","severity":"medium","exploited":false,"published_at":"2026-09-08T21:21:12+00:00","url":"https://junglewise.ai/threats/next-js-image-optimization-heap-buffer-overflow-via-avif-9ce530ed"},{"cve":"CVE-2026-75604","cvss":9,"epss":0.023,"slug":"cve-2026-75604-next-js-unauthenticated-remote-code-execution-on-windows","title":"Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Page","severity":"critical","exploited":false,"published_at":"2026-09-01T22:17:12.697+00:00","url":"https://junglewise.ai/threats/cve-2026-75604-next-js-unauthenticated-remote-code-execution-on-windows"},{"cvss":9.8,"slug":"next-js-and-libheif-rce-in-heif-avif-image-processing-eebb5345","title":"Next.js and libheif RCE in HEIF/AVIF image processing","severity":"info","exploited":false,"published_at":"2026-08-25T00:00:00+00:00","url":"https://junglewise.ai/threats/next-js-and-libheif-rce-in-heif-avif-image-processing-eebb5345"},{"cve":"CVE-2026-64649","cvss":4,"epss":0.0046,"slug":"cve-2026-64649-vercel-next-js-ssrf-in-server-actions-on-custom-servers","title":"Vercel Next.js SSRF in Server Actions on custom servers","severity":"high","exploited":false,"published_at":"2026-07-27T20:16:40.703+00:00","url":"https://junglewise.ai/threats/cve-2026-64649-vercel-next-js-ssrf-in-server-actions-on-custom-servers"},{"cve":"CVE-2026-64648","cvss":4,"epss":0.0034,"slug":"cve-2026-64648-vercel-next-js-cache-confusion-in-server-side-fetch","title":"Vercel Next.js cache confusion in server-side fetch","severity":"medium","exploited":false,"published_at":"2026-07-27T20:16:40.563+00:00","url":"https://junglewise.ai/threats/cve-2026-64648-vercel-next-js-cache-confusion-in-server-side-fetch"},{"cve":"CVE-2026-64647","cvss":4,"epss":0.0032,"slug":"cve-2026-64647-vercel-next-js-cache-confusion-in-server-side-fetch-requests","title":"Vercel Next.js cache confusion in server-side fetch requests","severity":"medium","exploited":false,"published_at":"2026-07-27T19:17:21.627+00:00","url":"https://junglewise.ai/threats/cve-2026-64647-vercel-next-js-cache-confusion-in-server-side-fetch-requests"},{"cve":"CVE-2026-64646","cvss":4,"epss":0.0052,"slug":"cve-2026-64646-vercel-next-js-denial-of-service-in-server-actions-edge-runtime","title":"Vercel Next.js denial of service in Server Actions Edge runtime","severity":"medium","exploited":false,"published_at":"2026-07-27T19:17:21.477+00:00","url":"https://junglewise.ai/threats/cve-2026-64646-vercel-next-js-denial-of-service-in-server-actions-edge-runtime"},{"cve":"CVE-2026-64645","cvss":4,"epss":0.0041,"slug":"cve-2026-64645-vercel-next-js-ssrf-and-open-redirect-in-rewrites-and-redirects","title":"Vercel Next.js SSRF and Open Redirect in rewrites and redirects","severity":"high","exploited":false,"published_at":"2026-07-27T18:16:59.453+00:00","url":"https://junglewise.ai/threats/cve-2026-64645-vercel-next-js-ssrf-and-open-redirect-in-rewrites-and-redirects"},{"cve":"CVE-2026-64644","cvss":4,"epss":0.0067,"slug":"cve-2026-64644-vercel-next-js-denial-of-service-in-image-optimization-api","title":"Vercel Next.js denial of service in Image Optimization API","severity":"medium","exploited":false,"published_at":"2026-07-27T18:16:59.307+00:00","url":"https://junglewise.ai/threats/cve-2026-64644-vercel-next-js-denial-of-service-in-image-optimization-api"},{"cve":"CVE-2026-64643","cvss":4,"epss":0.0051,"slug":"cve-2026-64643-vercel-next-js-authentication-bypass-in-server-function-endpoints","title":"Vercel Next.js authentication bypass in Server Function endpoints","severity":"medium","exploited":false,"published_at":"2026-07-27T18:16:59.16+00:00","url":"https://junglewise.ai/threats/cve-2026-64643-vercel-next-js-authentication-bypass-in-server-function-endpoints"},{"cve":"CVE-2026-64642","cvss":4,"epss":0.0064,"slug":"cve-2026-64642-vercel-next-js-authentication-bypass-in-turbopack-middleware","title":"Vercel Next.js authentication bypass in Turbopack middleware matcher","severity":"high","exploited":false,"published_at":"2026-07-27T18:16:59.01+00:00","url":"https://junglewise.ai/threats/cve-2026-64642-vercel-next-js-authentication-bypass-in-turbopack-middleware"},{"cve":"CVE-2026-64641","cvss":4,"epss":0.0086,"slug":"cve-2026-64641-vercel-next-js-denial-of-service-in-app-router-server-actions","title":"Vercel Next.js denial of service in App Router Server Actions","severity":"high","exploited":false,"published_at":"2026-07-27T18:16:58.85+00:00","url":"https://junglewise.ai/threats/cve-2026-64641-vercel-next-js-denial-of-service-in-app-router-server-actions"},{"cve":"CVE-2026-64651","cvss":6.3,"slug":"cve-2026-64651-vercel-ai-sdk-authorization-bypass-in-opencode-harness-tool-relay","title":"Vercel AI SDK authorization bypass in OpenCode harness tool relay","severity":"info","exploited":false,"published_at":"2026-07-20T21:16:50.677+00:00","url":"https://junglewise.ai/threats/cve-2026-64651-vercel-ai-sdk-authorization-bypass-in-opencode-harness-tool-relay"},{"cve":"CVE-2026-64650","cvss":6.3,"slug":"cve-2026-64650-vercel-ai-sdk-codex-harness-authorization-bypass-in-tool-relay","title":"Vercel AI SDK Codex harness authorization bypass in tool relay","severity":"info","exploited":false,"published_at":"2026-07-20T21:16:50.52+00:00","url":"https://junglewise.ai/threats/cve-2026-64650-vercel-ai-sdk-codex-harness-authorization-bypass-in-tool-relay"},{"cve":"CVE-2026-8769","cvss":4.3,"epss":0.0073,"slug":"cve-2026-8769-vercel-ai-sdk-denial-of-service-in-provider-utils-response-handler","title":"Vercel AI SDK denial of service in provider-utils response handler","severity":"medium","exploited":false,"published_at":"2026-05-17T23:17:03.18+00:00","url":"https://junglewise.ai/threats/cve-2026-8769-vercel-ai-sdk-denial-of-service-in-provider-utils-response-handler"},{"cve":"CVE-2026-8768","cvss":7.3,"slug":"cve-2026-8768-vercel-ai-ssrf-via-http-redirect-in-provider-utils","title":"Vercel AI SSRF via HTTP redirect in provider-utils","severity":"high","exploited":false,"published_at":"2026-05-17T23:17:02.997+00:00","url":"https://junglewise.ai/threats/cve-2026-8768-vercel-ai-ssrf-via-http-redirect-in-provider-utils"},{"cve":"CVE-2026-8767","cvss":5,"slug":"cve-2026-8767-vercel-ai-os-command-injection-in-github-actions-workflow","title":"Vercel AI OS command injection in GitHub Actions workflow","severity":"medium","exploited":false,"published_at":"2026-05-17T23:17:02.81+00:00","url":"https://junglewise.ai/threats/cve-2026-8767-vercel-ai-os-command-injection-in-github-actions-workflow"},{"cve":"CVE-2026-46508","cvss":8.4,"epss":0.0002,"slug":"cve-2026-46508-vercel-turborepo-command-injection-in-vs-code-extension","title":"Vercel Turborepo command injection in VS Code extension","severity":"info","exploited":false,"published_at":"2026-05-15T16:16:15.42+00:00","url":"https://junglewise.ai/threats/cve-2026-46508-vercel-turborepo-command-injection-in-vs-code-extension"},{"cve":"CVE-2026-45773","cvss":4,"epss":0.0018,"slug":"cve-2026-45773-vercel-turborepo-csrf-and-session-fixation-in-self-hosted-login","title":"Vercel Turborepo CSRF and session fixation in self-hosted login flow","severity":"medium","exploited":false,"published_at":"2026-05-15T16:16:15.137+00:00","url":"https://junglewise.ai/threats/cve-2026-45773-vercel-turborepo-csrf-and-session-fixation-in-self-hosted-login"},{"cve":"CVE-2026-45772","cvss":9.8,"epss":0.0064,"slug":"cve-2026-45772-vercel-turborepo-arbitrary-code-execution-via-malicious-yarn","title":"Vercel Turborepo arbitrary code execution via malicious Yarn configuration","severity":"critical","exploited":false,"published_at":"2026-05-15T16:16:14.987+00:00","url":"https://junglewise.ai/threats/cve-2026-45772-vercel-turborepo-arbitrary-code-execution-via-malicious-yarn"},{"cve":"CVE-2026-45109","cvss":7.5,"epss":0.0076,"slug":"cve-2026-45109-vercel-next-js-authentication-bypass-in-middleware-with-turbopack","title":"Vercel Next.js authentication bypass in middleware with Turbopack","severity":"high","exploited":false,"published_at":"2026-05-13T18:16:19.283+00:00","url":"https://junglewise.ai/threats/cve-2026-45109-vercel-next-js-authentication-bypass-in-middleware-with-turbopack"},{"cve":"CVE-2026-44582","cvss":3.7,"epss":0.0017,"slug":"cve-2026-44582-vercel-next-js-cache-poisoning-in-react-server-components","title":"Vercel Next.js cache poisoning in React Server Components","severity":"low","exploited":false,"published_at":"2026-05-13T18:16:19.037+00:00","url":"https://junglewise.ai/threats/cve-2026-44582-vercel-next-js-cache-poisoning-in-react-server-components"},{"cve":"CVE-2026-44581","cvss":4.7,"epss":0.0025,"slug":"cve-2026-44581-vercel-next-js-xss-in-app-router-via-csp-nonces","title":"Vercel Next.js stored XSS in App Router via CSP nonce reflection","severity":"medium","exploited":false,"published_at":"2026-05-13T18:16:18.4+00:00","url":"https://junglewise.ai/threats/cve-2026-44581-vercel-next-js-xss-in-app-router-via-csp-nonces"},{"cve":"CVE-2026-44580","cvss":6.1,"epss":0.0025,"slug":"cve-2026-44580-vercel-next-js-xss-in-beforeinteractive-scripts","title":"Vercel Next.js cross-site scripting in beforeInteractive scripts","severity":"medium","exploited":false,"published_at":"2026-05-13T18:16:18.26+00:00","url":"https://junglewise.ai/threats/cve-2026-44580-vercel-next-js-xss-in-beforeinteractive-scripts"}],"vendor":{"hub":true,"name":"Vercel","slug":"vercel","description":"Cloud platform for deploying and hosting web applications and serverless functions.","url":"https://junglewise.ai/threats/vendors/vercel"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":9},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":1,"exploited":0,"vulnerabilities":1},{"week":"2026-09-07","critical":1,"exploited":0,"vulnerabilities":2},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2025-55182","cvss":10,"epss":0.998,"slug":"cve-2025-55182-meta-react-server-components-remote-code-execution","title":"A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclu","severity":"critical","exploited":true,"published_at":"2025-12-03T16:15:56.463+00:00","url":"https://junglewise.ai/threats/cve-2025-55182-meta-react-server-components-remote-code-execution"},{"cve":"CVE-2026-45772","cvss":9.8,"epss":0.0064,"slug":"cve-2026-45772-vercel-turborepo-arbitrary-code-execution-via-malicious-yarn","title":"Vercel Turborepo arbitrary code execution via malicious Yarn configuration","severity":"critical","exploited":false,"published_at":"2026-05-15T16:16:14.987+00:00","url":"https://junglewise.ai/threats/cve-2026-45772-vercel-turborepo-arbitrary-code-execution-via-malicious-yarn"},{"cvss":9.5,"slug":"next-js-heap-buffer-overflow-in-image-optimization-via-malicious-avif-90b951e0","title":"Next.js heap buffer overflow in image optimization via malicious AVIF","severity":"critical","exploited":false,"published_at":"2026-09-08T21:21:12+00:00","url":"https://junglewise.ai/threats/next-js-heap-buffer-overflow-in-image-optimization-via-malicious-avif-90b951e0"},{"cve":"CVE-2026-75604","cvss":9,"epss":0.023,"slug":"cve-2026-75604-next-js-unauthenticated-remote-code-execution-on-windows","title":"Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Page","severity":"critical","exploited":false,"published_at":"2026-09-01T22:17:12.697+00:00","url":"https://junglewise.ai/threats/cve-2026-75604-next-js-unauthenticated-remote-code-execution-on-windows"},{"cve":"CVE-2026-44578","cvss":8.6,"epss":0.019,"slug":"cve-2026-44578-vercel-next-js-ssrf-via-websocket-upgrade-requests","title":"Vercel Next.js SSRF via WebSocket upgrade requests","severity":"high","exploited":false,"published_at":"2026-05-13T18:16:17.99+00:00","url":"https://junglewise.ai/threats/cve-2026-44578-vercel-next-js-ssrf-via-websocket-upgrade-requests"},{"cve":"CVE-2026-44574","cvss":8.1,"epss":0.0067,"slug":"cve-2026-44574-vercel-next-js-authorization-bypass-in-dynamic-route-middleware","title":"Vercel Next.js authorization bypass in dynamic route middleware","severity":"high","exploited":false,"published_at":"2026-05-13T17:16:22.767+00:00","url":"https://junglewise.ai/threats/cve-2026-44574-vercel-next-js-authorization-bypass-in-dynamic-route-middleware"},{"cve":"CVE-2026-23870","cvss":7.5,"epss":0.0153,"slug":"cve-2026-23870-facebook-react-denial-of-service-in-react-server-components","title":"Facebook React Denial of Service in React Server Components","severity":"high","exploited":false,"published_at":"2026-05-11T14:50:07+00:00","url":"https://junglewise.ai/threats/cve-2026-23870-facebook-react-denial-of-service-in-react-server-components"},{"cve":"CVE-2026-45109","cvss":7.5,"epss":0.0076,"slug":"cve-2026-45109-vercel-next-js-authentication-bypass-in-middleware-with-turbopack","title":"Vercel Next.js authentication bypass in middleware with Turbopack","severity":"high","exploited":false,"published_at":"2026-05-13T18:16:19.283+00:00","url":"https://junglewise.ai/threats/cve-2026-45109-vercel-next-js-authentication-bypass-in-middleware-with-turbopack"},{"cve":"CVE-2026-44579","cvss":7.5,"epss":0.0076,"slug":"cve-2026-44579-vercel-next-js-connection-exhaustion-in-cache-components","title":"Vercel Next.js connection exhaustion in Cache Components","severity":"high","exploited":false,"published_at":"2026-05-13T18:16:18.123+00:00","url":"https://junglewise.ai/threats/cve-2026-44579-vercel-next-js-connection-exhaustion-in-cache-components"},{"cve":"CVE-2026-44575","cvss":7.5,"epss":0.0076,"slug":"cve-2026-44575-vercel-next-js-auth-bypass-in-app-router-middleware","title":"Vercel Next.js auth bypass in App Router middleware","severity":"high","exploited":false,"published_at":"2026-05-13T17:16:22.907+00:00","url":"https://junglewise.ai/threats/cve-2026-44575-vercel-next-js-auth-bypass-in-app-router-middleware"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"Vercel Next.js","slug":"next-js","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/next-js"},{"name":"Vercel AI SDK","slug":"ai-sdk","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/ai-sdk"},{"name":"Vercel Turbo","slug":"turbo","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/turbo"}]}