vercel
7 records · 7 with a public proof-of-concept
Disclosed vulnerabilities where the NVD names vercel as an affected vendor, highest CVSS first.
- MEDIUM 6.5CVE-2026-94483public PoC
Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, Image Optimization can follow attacker-controlled DNS resolution for a remote URL that matches images.remotePatterns, allowing the optimized image fetch to reach p…
next.js
- MEDIUM 5.4CVE-2026-94486public PoC
Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the next dev development server exposes a Model Context Protocol endpoint without reliably restricting cross-site requests. A malicious website visited by a develo…
next.js
- MEDIUM 5.3CVE-2026-94543public PoC
Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated or Incremental Static Regeneration pages can key a response cache entry witho…
next.js
- MEDIUM 5.3CVE-2026-94485public PoC
Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the `next dev` development server exposes a Model Context Protocol endpoint without reliably restricting cross-site requests. A malicious website visited by a deve…
next.js
- MEDIUM 5.3CVE-2026-103004public PoC
Next.js versions from 16.3.0 to 16.3.7 warm `use cache` handlers using `next/root-params` and can leak their return value to pages with different root params. With Cache Components enabled (cacheComponents: true), a 'use cache' function that calls another 'use…
next.js
- MEDIUM 4.8CVE-2026-94484public PoC
Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, applications with a root-level catch-all page and statically generated or Incremental Static Regeneration routes can use a shared response cache key th…
next.js
- MEDIUM 4.2CVE-2026-94544public PoC
Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without separating Draft Mode requests from regular requests. An overlapping regular request can receive unauth…
next.js