CVE-2025-59471
- CVSS
- —
- EPSS
- 0.005 (39.8th percentile)
- CISA KEV
- Not listed
- Exploitation
- No report
- Public exploits
- None seen
- State
- Unknown
Coverage
Vercel (blog + changelog)
Summaries of CVE-2025-59471 and CVE-2025-59472
Two medium-severity denial-of-service vulnerabilities were discovered in self-hosted Next.js applications. Both issues can cause server crashes through memory exhaustion under specific configurations. No data exposure or privilege escalation is possible. Applications hosted on Vercel’s platform are…
What we observed
No signals recorded