VulnSea

vercel has 7 CVEs on record. Disclosures have slowed: 0 in the last 90 days after 7 in the 90 before. The busiest recent month was May 2026 with 7. The median CVSS is 7.5 (high). None have a confirmed exploitation report. The dominant weakness classes are CWE-288 (3) and CWE-551 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
0 prev 7

Products

  • next.js 7
7
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

vercel vulnerabilities

CVEs affecting vercel, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

CVE-2026-45109High· 7.5
4mo ago

Next.js is a React framework for building full-stack web applications

Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fix…

Twilightvercel · next.jsEPSS 0.57%via NVD
CVE-2026-44579High· 7.5PoC
4mo ago

Next.js is a React framework for building full-stack web applications

Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through cr…

Midnightvercel · next.jsEPSS 0.75%via NVD
CVE-2026-44578High· 8.6PoC
4mo ago

Next.js is a React framework for building full-stack web applications

Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted…

Midnightvercel · next.jsEPSS 39%via NVD
CVE-2026-44577Medium· 5.9
4mo ago

Next.js is a React framework for building full-stack web applications

Next.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memor…

Sunlitvercel · next.jsEPSS 0.74%via NVD
CVE-2026-44575High· 7.5
4mo ago

Next.js is a React framework for building full-stack web applications

Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access throug…

Twilightvercel · next.jsEPSS 1.6%via NVD
CVE-2026-44574High· 8.1
4mo ago

Next.js is a React framework for building full-stack web applications

Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deploy…

Twilightvercel · next.jsEPSS 0.64%via NVD
CVE-2026-44573High· 7.5
4mo ago

Next.js is a React framework for building full-stack web applications

Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized acc…

Twilightvercel · next.jsEPSS 0.62%via NVD
vercel vulnerabilities (CVEs) · VulnSea