Skip to content

[GHSA-866g-f22w-33x8] @ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue - #8972

Closed
tractorcow wants to merge 1 commit into
tractorcow/advisory-improvement-8972from
tractorcow-GHSA-866g-f22w-33x8
Closed

[GHSA-866g-f22w-33x8] @ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue#8972
tractorcow wants to merge 1 commit into
tractorcow/advisory-improvement-8972from
tractorcow-GHSA-866g-f22w-33x8

Conversation

@tractorcow

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3
  • CVSS v4
  • Description
  • Severity

Comments
Fix is in @ai-sdk/provider-utils changelogs and matching commits: 3.0.28 (b85c4fb), 4.0.33 (b30e43a), 5.0.1 (6a436e3). Affected: < 3.0.28, >= 4.0.0 < 4.0.33, >= 5.0.0 < 5.0.1. Note: published npm has no 3.0.97; current <= 3.0.97 / “Patched: None” is incorrect.

Copilot AI review requested due to automatic review settings August 4, 2026 01:35
@github-actions
github-actions Bot changed the base branch from main to tractorcow/advisory-improvement-8972 August 4, 2026 01:36
@tractorcow

Copy link
Copy Markdown
Author

Sorry, the CVSS was not ment to be changed as a part of this submission, only the affected version.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates GHSA-866g-f22w-33x8 with corrected affected versions and severity data.

Changes:

  • Adds patched ranges for versions 3.x, 4.x, and 5.x.
  • Updates the description and CVSS v4 severity.
  • Raises severity from low to high.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

"schema_version": "1.4.0",
"id": "GHSA-866g-f22w-33x8",
"modified": "2026-05-29T16:18:57Z",
"modified": "2026-05-29T16:18:59Z",
],
"summary": "@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue",
"details": "A vulnerability was determined in Vercel AI up to 3.0.97. The impacted element is the function `createJsonResponseHandler/createJsonErrorResponseHandler` of the file `packages/provider-utils/src/response-handler.ts` of the component `provider-utils`. This manipulation causes resource consumption. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.",
"details": "A vulnerability was determined in @ai-sdk/provider-utils up to (and including) 3.0.27. The impacted element is the function `createJsonResponseHandler/createJsonErrorResponseHandler` of the file `packages/provider-utils/src/response-handler.ts` of the component `provider-utils`. This manipulation causes resource consumption. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.",
@tractorcow tractorcow closed this Aug 4, 2026
@tractorcow

Copy link
Copy Markdown
Author

Will address feedback in a new submission.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants