Vulnerabilities/

@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue

Severity:
Low

Description

A vulnerability was determined in Vercel AI up to 3.0.97. The impacted element is the function createJsonResponseHandler/createJsonErrorResponseHandler of the file packages/provider-utils/src/response-handler.ts of the component provider-utils. This manipulation causes resource consumption. The attack may be initiated remotely.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
@ai-sdk/provider-utils
Anything's wrong? Let us know Last updated on May 29, 2026