Summaries of CVE-2025-59471 and CVE-2025-59472
Two medium-severity denial-of-service vulnerabilities were discovered in self-hosted Next.js applications. Both issues can cause server crashes through memory exhaustion under specific configurations. No data exposure or privilege escalation is possible. Applications hosted on Vercel’s platform are…
Sources
- T1Summaries of CVE-2025-59471 and CVE-2025-59472Vercel (blog + changelog)