Description
A vulnerability was determined in Vercel AI up to 3.0.97. The impacted element is the function createJsonResponseHandler/createJsonErrorResponseHandler of the file packages/provider-utils/src/response-handler.ts of the component provider-utils. This manipulation causes resource consumption. The attack may be initiated remotely.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 3.0.97
References
Related Issues
- @isaacs/brace-expansion has Uncontrolled Resource Consumption - CVE-2026-25547
- DesktopCommanderMCP is vulnerable to Uncontrolled Resource Consumption - CVE-2026-10691
- @tinacms/graphql has a Path Traversal issue - CVE-2026-24125
- Uncontrolled Resource Consumption in markdown-it - CVE-2022-21670
You might also like:
- Tags:
- npm
- @ai-sdk/provider-utils
Anything's wrong? Let us know Last updated on May 29, 2026


