Known vulnerabilities in vercel Next.js 14.1.1

Vendor: vercel
Website: https://github.com/vercel
Total Security Bulletins: 14

Security bulletins (14)

Secuity bulletin Severity Status Published
SB2026012703: Next.js update for React Server Components Medium
Patched
27.01.2026
SB2026012662: Two DoS vulnerabilities in Next.js Medium
Patched
26.01.2026
SB2025121222: Denial of service in Next.js React Server Components Medium
Patched
12.12.2025
SB2025121220: Denial of service in Next.js App Router Medium
Patched Public exploit
12.12.2025
SB2025083005: Use of cache containing sensitive information in Next.js Medium
Patched
30.08.2025
SB2025083004: External image manipulation in Next.js Low
Patched
30.08.2025
SB2025083002: SSRF in Next.js Medium
Patched
30.08.2025
SB2025051603: Cache poisoning in Next.js Low
Patched Public exploit
16.05.2025
SB2025040314: Information disclosure in Next.js Low
Patched
03.04.2025
SB2025032132: Authorization bypass in Next.js High
Patched Public exploit
21.03.2025
SB2025012133: Authorization bypass in Next.js Medium
Patched
21.01.2025
SB2025012132: Denial of service in Next.js Medium
Patched
21.01.2025
SB2024101466: Denial of service in Next.js image optimization Medium
Patched
14.10.2024
SB2024091832: Cache poisoning in Next.js Medium
Patched Public exploit
18.09.2024