Vulnerabilidades em vercel

65 resultados
Análise Vexday

O ecossistema de vulnerabilidades do Vercel soma 52 CVEs catalogadas, com uma taxa de exploração ativa abaixo da média geral do catálogo KEV — nenhuma das falhas conhecidas consta atualmente como explorada ativamente pela CISA. Apesar disso, o volume recente é expressivo: 19 CVEs surgiram nos últimos 90 dias, o que indica aceleração no ritmo de descoberta e exige acompanhamento contínuo. O ponto de maior atenção é CVE-2025-29927, única CVE crítica catalogada e com EPSS de 0,9962 — valor próximo ao máximo da escala, sinalizando probabilidade muito elevada de exploração ativa em breve, mesmo sem confirmação formal no KEV. O tipo de falha dominante, CWE-400 (consumo descontrolado de recursos), combinado com cinco CVEs que possuem PoC pública, reforça a necessidade de priorizar a aplicação de correções, especialmente para equipes com superfície de exposição direta à plataforma.

CVE-2024-47831MEDIUMNext.js image optimization has Denial of Service conditionEPSS 0.7%CVE-2026-44577MEDIUMNext.js: Denial of Service in the Image Optimization APIEPSS 0.7%CVE-2025-32421LOWNext.js Race Condition to Cache PoisoningEPSS 0.7%CVE-2026-44579HIGHNext.js: Denial of Service via connection exhaustion in applications using Cache ComponentsEPSS 0.7%CVE-2026-27980MEDIUMNext.js: Unbounded next/image disk cache growth can exhaust storageEPSS 0.7%CVE-2026-64644MEDIUMNext.js: Denial of Service in the Image Optimization API using SVGsEPSS 0.7%CVE-2026-27979MEDIUMNext.js: Unbounded postponed resume buffering can lead to DoSEPSS 0.7%CVE-2026-44574HIGHNext.js: Middleware / Proxy bypass through dynamic route parameter injectionEPSS 0.6%CVE-2026-44573HIGHNext.js: Middleware / Proxy bypass in Pages Router applications using i18nEPSS 0.6%CVE-2026-64641HIGHNext.js: Denial of Service in App Router using Server ActionsEPSS 0.6%CVE-2026-8769MEDIUMvercel ai provider-utils response-handler.ts createJsonErrorResponseHandler resource consumptionEPSS 0.6%CVE-2026-45109HIGHNext.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routesEPSS 0.6%CVE-2025-7074MEDIUMvercel hyper rimraf-standalone.js ignoreMap redosEPSS 0.6%CVE-2025-55173MEDIUMNext.js Content Injection Vulnerability for Image OptimizationEPSS 0.5%CVE-2026-64646MEDIUMNext.js: Unbounded Server Action payload in Edge runtimeEPSS 0.5%CVE-2026-64643MEDIUMNext.js: Unauthenticated Disclosure of Internal Server Function endpointsEPSS 0.5%CVE-2024-39693HIGHNext.js Denial of Service (DoS) conditionEPSS 0.5%CVE-2026-64649HIGHNext.js: Server-Side Request Forgery in Server Actions on Custom ServersEPSS 0.4%CVE-2025-59471MEDIUMA denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. EPSS 0.4%CVE-2026-29057MEDIUMNext.js: HTTP request smuggling in rewritesEPSS 0.4%