Description
A vulnerability was determined in Vercel AI up to 3.0.97. The impacted element is the function createJsonResponseHandler/createJsonErrorResponseHandler of the file packages/provider-utils/src/response-handler.ts of the component provider-utils. This manipulation causes resource consumption. The attack may be initiated remotely.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 3.0.97
References
Could your website be exposed too?
SmartScanner can check your website for @ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue and gives you actionable findings to investigate.
Start a free scanRelated Issues
- @isaacs/brace-expansion has Uncontrolled Resource Consumption - CVE-2026-25547
- DesktopCommanderMCP is vulnerable to Uncontrolled Resource Consumption - CVE-2026-10691
- @tinacms/graphql has a Path Traversal issue - CVE-2026-24125
- Uncontrolled Resource Consumption in markdown-it - CVE-2022-21670


