Vulnerabilidades en Vercel

66 resultados
Análisis Vexday

Vercel possui apenas 2 vulnerabilidades registradas na base do Vexday, nenhuma delas sob ataque ativo ou classificada como crítica, representando um perfil de risco baixo. A fraqueza dominante é relacionada a validação de entrada (CWE-20), mas sem atividade recente de publicações, indicando que o cenário de risco permanece estável e não apresenta exposições imediatas.

CVE-2026-8768MEDIUMvercel ai provider-utils download-blob.ts validateDownloadUrl server-side request forgeryEPSS 0.5%CVE-2026-29057MEDIUMNext.js: HTTP request smuggling in rewritesEPSS 0.4%CVE-2025-49005LOWNext.js cache poisoning due to omission of Vary headerEPSS 0.4%CVE-2025-30218LOWNext.js may leak x-middleware-subrequest-id to external hostsEPSS 0.4%CVE-2026-45772NONETurborepo: Unexpected local code execution during Yarn Berry detectionEPSS 0.4%CVE-2025-59472MEDIUMA denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in minimal mode. The PPR rEPSS 0.4%CVE-2026-64647MEDIUMNext.js: Response Body Cache Confusion with Invalid UTF-8 Request BodiesEPSS 0.4%CVE-2025-57752MEDIUMNext.js Affected by Cache Key Confusion for Image Optimization API RoutesEPSS 0.3%CVE-2026-64648MEDIUMNext.js: Response Body Cache Confusion for Requests Containing BodiesEPSS 0.3%CVE-2025-46332MEDIUMInformation Disclosure via Flags override linkEPSS 0.3%CVE-2026-44576MEDIUMNext.js: Cache poisoning in React Server Component responsesEPSS 0.3%CVE-2026-44572LOWNext.js: Middleware / Proxy redirects can be cache-poisonedEPSS 0.3%CVE-2025-48985LOWA vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypEPSS 0.3%CVE-2025-52662MEDIUMA vulnerability in Nuxt DevTools has been fixed in version **2.6.4***. This issue may have allowed Nuxt auth token extraction via XSS under EPSS 0.2%CVE-2024-24828MEDIUMLocal Privilege Escalation in execuatables bundled by pkgEPSS 0.2%CVE-2026-44581MEDIUMNext.js: Cross-site scripting in App Router applications using CSP noncesEPSS 0.2%CVE-2026-44582LOWNext.js: Cache poisoning via collisions in React Server Component cache-bustingEPSS 0.2%CVE-2026-44580MEDIUMNext.js: Cross-site scripting in beforeInteractive scripts with untrusted inputEPSS 0.2%CVE-2026-27978MEDIUMNext.js: null origin can bypass Server Actions CSRF checksEPSS 0.2%CVE-2025-48068LOWInformation exposure in Next.js dev server due to lack of origin verificationEPSS 0.2%