Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Vercel

First CVE: Jan 23, 2017Active for: 9 yearsTotal CVEs: 60
74.5
VTI Score
TOP TARGET

Vercel's vulnerability footprint centers on a focused portfolio of web-application frameworks and deployment infrastructure, with Next.js as the flagship product and supporting tools such as its AI, Hyper, and serverless platform components. The exposure is characterized by resource-consumption and request-handling weaknesses, particularly uncontrolled resource exhaustion, allocation without limits, HTTP request smuggling, and server-side request forgery, reflecting the attack surface inherent to a JavaScript-based full-stack framework and edge-compute platform. A meaningful share of the vendor's disclosures reach serious severity, and vulnerabilities here show a moderate tendency toward public exploit availability, underscoring the operational importance of these frameworks in production environments. Defenders should monitor Next.js releases closely given its prevalence in modern web applications and prioritize patches addressing resource exhaustion and request-smuggling conditions; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
60
Total CVEs
More Total CVEs than 99% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 45% of tracked vendors
1.7%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Vercel over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 23, 2017
9 years ago
Most Recent CVE
May 17, 2026
68 days ago

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (60 CVEs).

60 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-55182CRITICAL
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-serve
Dec 3, 202510.099YESYES
CVE-2025-29927CRITICAL
Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypas
Mar 21, 20259.194NOYES
CVE-2025-55184HIGH
A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following pa
Dec 11, 20257.583NOYES
CVE-2026-44578HIGH
Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be
May 13, 20268.675NOYES
CVE-2025-55183MEDIUM
An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the foll
Dec 11, 20255.368NONO
CVE-2024-46982HIGH
Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible to poison the cache of a non-dynamic server-side rendered r
Sep 17, 20247.559NONO
CVE-2025-67779HIGH
It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Compo
Dec 12, 20257.550NONO
CVE-2021-43803HIGH
Next.js is a React framework. In versions of Next.js prior to 12.0.5 or 11.1.3, invalid or malformed URLs could lead to a server crash. In order to be affected by this issue, the d
Dec 10, 20217.549NONO
CVE-2025-57822HIGH
Next.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next() was used without explicitly passing the request object, it
Aug 29, 20258.241NOYES
CVE-2024-34351HIGH
Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server Action
May 14, 20247.538NOYES
View all 60 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products60 CVEs
37%
52%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (6.7%)
Network56 (93.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low51 (85.0%)
High9 (15.0%)
Unknown0 (0.0%)
User Interaction
None48 (80.0%)
Unknown0 (0.0%)
Required12 (20.0%)
Privileges Required
Low5 (8.3%)
High0 (0.0%)
None55 (91.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (60 CVEs).

CISA KEV
1 CVE
1.7% of CVEs· 99th percentile
Metasploit
2 CVEs
3.3% of CVEs· 98th percentile
Nuclei
6 CVEs
10.0% of CVEs· 96th percentile
ExploitDB
2 CVEs
3.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Vercel.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Vercel — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Vercel's Products

View all 5 CNAs →

Top CWEs