Vercel's vulnerability footprint centers on a focused portfolio of web-application frameworks and deployment infrastructure, with Next.js as the flagship product and supporting tools such as its AI, Hyper, and serverless platform components. The exposure is characterized by resource-consumption and request-handling weaknesses, particularly uncontrolled resource exhaustion, allocation without limits, HTTP request smuggling, and server-side request forgery, reflecting the attack surface inherent to a JavaScript-based full-stack framework and edge-compute platform. A meaningful share of the vendor's disclosures reach serious severity, and vulnerabilities here show a moderate tendency toward public exploit availability, underscoring the operational importance of these frameworks in production environments. Defenders should monitor Next.js releases closely given its prevalence in modern web applications and prioritize patches addressing resource exhaustion and request-smuggling conditions; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vercel over time
Signals from CVEs in this vendor scope (60 CVEs).
60 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-55182CRITICAL A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-serve | Dec 3, 2025 | 10.0 | 99 | YES | YES |
CVE-2025-29927CRITICAL Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypas | Mar 21, 2025 | 9.1 | 94 | NO | YES |
CVE-2025-55184HIGH A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following pa | Dec 11, 2025 | 7.5 | 83 | NO | YES |
CVE-2026-44578HIGH Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be | May 13, 2026 | 8.6 | 75 | NO | YES |
CVE-2025-55183MEDIUM An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the foll | Dec 11, 2025 | 5.3 | 68 | NO | NO |
CVE-2024-46982HIGH Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible to poison the cache of a non-dynamic server-side rendered r | Sep 17, 2024 | 7.5 | 59 | NO | NO |
CVE-2025-67779HIGH It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Compo | Dec 12, 2025 | 7.5 | 50 | NO | NO |
CVE-2021-43803HIGH Next.js is a React framework. In versions of Next.js prior to 12.0.5 or 11.1.3, invalid or malformed URLs could lead to a server crash. In order to be affected by this issue, the d | Dec 10, 2021 | 7.5 | 49 | NO | NO |
CVE-2025-57822HIGH Next.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next() was used without explicitly passing the request object, it | Aug 29, 2025 | 8.2 | 41 | NO | YES |
CVE-2024-34351HIGH Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server Action | May 14, 2024 | 7.5 | 38 | NO | YES |
Signals from CVEs in this vendor scope (60 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vercel.
Media articles that mention a CVE ID that affects a product developed by Vercel — matched by CVE ID, not by vendor name.