CVE-2026-8769 Details
Description
A vulnerability was determined in vercel ai up to 3.0.97. The impacted element is the function createJsonResponseHandler/createJsonErrorResponseHandler of the file packages/provider-utils/src/response-handler.ts of the component provider-utils. This manipulation causes resource consumption. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
A denial-of-service vulnerability has been identified in the Vercel AI SDK, specifically in the '@ai-sdk/provider-utils' package, all versions prior to 3.0.97. The issue arises in the response handling functions 'createJsonResponseHandler' and 'createJsonErrorResponseHandler', located in 'packages/provider-utils/src/response-handler.ts'. These functions lack proper response size limitations when processing full text or JSON payloads from backend AI providers. As a result, a malicious provider can stream an infinite response, causing the Node.js application to exhaust its memory and crash. This vulnerability can be exploited remotely, leading to a high-impact denial-of-service condition for all active sessions on the affected server.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/YLChen-007/fb1096bc8428bed9a428f764d9d103bb | [email protected] | ExploitThird Party Advisory |
| https://vuldb.com/submit/811406 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/vuln/364394 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/vuln/364394/cti | [email protected] | Permissions RequiredVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
| CWE-404 | Improper Resource Shutdown or Release | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| vercel ai | <= 3.0.97 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 19, 2026 | Initial Analysis | [email protected] |
| May 17, 2026 | New CVE Received | [email protected] |