vercel has 7 CVEs on record. Disclosures have slowed: 0 in the last 90 days after 7 in the 90 before. The busiest recent month was May 2026 with 7. The median CVSS is 7.5 (high). None have a confirmed exploitation report. The dominant weakness classes are CWE-288 (3) and CWE-551 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 0 prev 7
Worst active — by depth score
CVE-2026-44578High· 8.6Next.js is a React framework for building full-stack web applications67CVE-2026-44579High· 7.5Next.js is a React framework for building full-stack web applications53CVE-2026-44574High· 8.1Next.js is a React framework for building full-stack web applications45CVE-2026-44575High· 7.5Next.js is a React framework for building full-stack web applications42CVE-2026-45109High· 7.5Next.js is a React framework for building full-stack web applications41
vercel vulnerabilities
CVEs affecting vercel, newest first. Open any entry for full detail, references, and exploit status.
7 CVEsRSS
CVE-2026-45109High· 7.5Next.js is a React framework for building full-stack web applications
Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fix…
CVE-2026-44579High· 7.5PoCNext.js is a React framework for building full-stack web applications
Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through cr…
CVE-2026-44578High· 8.6PoCNext.js is a React framework for building full-stack web applications
Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted…
CVE-2026-44577Medium· 5.9Next.js is a React framework for building full-stack web applications
Next.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memor…
CVE-2026-44575High· 7.5Next.js is a React framework for building full-stack web applications
Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access throug…
CVE-2026-44574High· 8.1Next.js is a React framework for building full-stack web applications
Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deploy…
CVE-2026-44573High· 7.5Next.js is a React framework for building full-stack web applications
Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized acc…