{"collection":{"slug":"application-platforms","name":"Application Platforms"},"digest":{"id":"cwd_xI839loUxwo9drwZIwFTK","weekStart":"2026-06-08","title":"Security hardening week across the AI SDK and Workers edge","intro":"Vercel's AI SDK received coordinated security patches for SSRF, credential exfiltration, and prototype pollution vulnerabilities across a dozen provider packages, while Cloudflare shipped new WAF rules for Ghost CMS SQL injection and threat intelligence integration.","body":"### Security patches sweep the AI SDK\n\nThis week's dominant story is a coordinated security release across the Vercel AI SDK. Multiple vulnerabilities were identified and patched in a single day, affecting the core runtime and nearly every provider adapter.\n\nThe most critical fix addresses a Server-Side Request Forgery (SSRF) vulnerability in the download URL validation. The `validateDownloadUrl` function and the `downloadBlob`/`download` helpers were found to be bypassable in several ways: a fully-qualified hostname with a trailing dot (e.g., `localhost.`) skipped the localhost blocklist, IPv6 addresses embedding an IPv4 address in their last 32 bits could bypass detection, and the `validateDownloadUrl` guard wasn't applied to redirect targets. This was fixed across three major versions: [ai@5.0.200](/release/rel_CAq7HtRGGfAXEZC5mWjTY-ai-sdk-ai-5-0-200-hardens-download-url-ssrf-guard-and-redacts-server-errors), [ai@6.0.203](/release/rel_ppEEkqbPEwx0ljecbZSOH-ai-sdk-ai-6-0-203-hardens-download-url-ssrf-and-redacts-server-error-details), and the canary branch [ai@7.0.0-canary.172](/release/rel_liFs5ye75WsPQ_jVd0UXn-ai-sdk-ai-7-0-0-canary-172-hardens-download-url-ssrf-guard-and-redacts-errors), the latter of which also removed deprecated experimental `generateImage` exports.\n\nA second class of vulnerability involved credential exfiltration. Several provider clients would follow a URL returned by the provider's API response (for polling, status, or media URLs) and reuse the authenticated headers — or append `?key=<API_KEY>` — on that request. Because the host of the response-supplied URL was never validated, an attacker who controlled that URL could capture the API key. This was patched across the [Fireworks](/release/rel_J_w4JnZNzRo_sFqAftbK8-ai-sdk-ai-sdk-fireworks-1-0-41-prevents-credential-exfiltration) and [Google](/release/rel_F7r2s6feDD7vAEdBgsKWy-ai-sdk-google-provider-3-0-82-prevents-prototype-pollution-and-credential) providers, with the Google fix also addressing prototype pollution when streaming tool arguments.\n\nThe MCP client saw two patches: prototype-named tools like `constructor` or `__proto__` could bypass the `schemas` allowlist because the check used the `in` operator instead of `Object.hasOwn` — fixed in [@ai-sdk/mcp@1.0.49](/release/rel_sbRGd-c779LX5IYqm4yXx-ai-sdk-ai-sdk-mcp-1-0-49-prevents-prototype-named-tools-from-bypassing-allowlist) and [@ai-sdk/mcp@0.0.19](/release/rel_6Ld0o4EjVViiGKW-Z4-kC-ai-sdk-ai-sdk-mcp-0-0-19-locks-first-sse-endpoint-and-prevents-prototype-tool). Both also locked the first SSE endpoint received via event to prevent endpoint switching. The AI Gateway followed with [@ai-sdk/gateway@2.0.101](/release/rel_o9nV-woeamWQI_NvWBVwD-ai-sdk-ai-sdk-gateway-2-0-101-maps-forbidden-errors-to-gatewayforbiddenerror) and [Gateway v3.0.131](/release/rel_KCcdrZScoFhzSaFAkhLn2-ai-sdk-gateway-v3-0-131-surfaces-provider-warnings-and-maps-forbidden-errors) mapping forbidden errors to `GatewayForbiddenError` instead of `GatewayInternalServerError`, the latter also surfacing provider warnings in embedding and reranking responses. Finally, [AI SDK devtools@0.0.19](/release/rel_1ZbA5lqJMFuE4GnscX1w8-ai-sdk-devtools-0-0-19-fixes-secured-api-access) secured the devtools viewer API access.\n\n### Cloudflare edge security: WAF rules and threat intelligence\n\nOn the Cloudflare side, the Application Security team shipped two significant WAF releases. The [WAF release of 2026-06-15](/release/rel_lLpAiqyCos_Vh9lKYJKmA-waf-waf-release-2026-06-15) introduced new managed protection for a critical SQL injection vulnerability in Ghost CMS (CVE-2026-26980) and a generic rule targeting sophisticated SQLi bypass attempts using obfuscated boolean logic — both deployed at the network edge before traffic reaches the origin.\n\nMore strategically, Cloudflare now lets you [match WAF rules against Cloudforce One threat intelligence](/release/rel_bL79mjnkL9eO8CZdbBV6Y-waf-use-cloudforce-one-threat-intelligence-in-waf-rules). A new detection looks up each request's client IP against the threat intelligence database. If the IP was involved in threat activity in the past seven days, Cloudflare populates `cf.intel.ip.*` fields that you can use in custom rules and rate limiting rules. This brings real-time threat data directly into the WAF rule engine, a significant upgrade for teams that need to block known bad actors without maintaining their own IP blocklists.\n\n### Vercel platform: Blob limits, Workflow in Nitro, and CLI improvements\n\nVercel raised the [Hobby Blob store limit from 5 to 100](/release/rel_CGZeLjNzOHrp6WLDbjOxk-vercel-raises-hobby-blob-store-limit-from-5-to-100), giving hobby-tier teams the flexibility to organize data by project, environment, or region without hitting artificial constraints. Storage, operations, and transfer limits still apply, but the 20x increase removes a common friction point for growing applications.\n\nThe [Vercel Workflow SDK now runs natively in Nitro v3](/release/rel_k_P5niuFY9yzwbJJRjOc0-vercel-workflow-sdk-now-runs-natively-in-nitro-v3) in beta. Steps run inside the same bundled runtime as the rest of your app, letting you use Nitro's `useStorage()` and other server-side APIs directly inside `\"use step\"` functions. The dev server also serves a workflow web UI at `/_workflow` for inspecting, monitoring, and debugging runs. Workflow routes are now bundled by Nitro with dependency tracing and tree-shaking, promising faster builds and smaller bundles.\n\nThe Vercel CLI saw user-facing improvements: `vercel@54.13.0` added a `--category` filter to `vercel integration discover` and a new `vercel integration categories` subcommand, while `vercel@54.14.0` introduced `ai-gateway rules` commands for adding, listing, editing, and removing rules. The [@vercel/frameworks@3.29.0](/release/rel_nt-g7A4JHxdR3XTa6KuOO-vercel-cli-vercel-frameworks-3-29-0-adds-bun-preset-and-graduates-eve) package graduated the Eve framework from experimental and added a Bun preset.\n\n### Next.js canary and Turborepo fixes\n\nThe [Next.js v16.3.0-canary.51](/release/rel_AMDjhXwgsW8JnVunzbGTz-next-js-v16-3-0-canary-51-avoids-premature-suspense-fallback-flash) avoids a premature Suspense fallback flash in the streaming dev render, while [v16.3.0-canary.49](/release/rel_o0BcprjBN86_ppO-2YEAa-next-js-v16-3-0-canary-49-warns-on-prefetch-true-navigation) adds a warning for `prefetch={true}` navigation when Partial Prefetching is not enabled, and serves stale `'use cache'` entries until they expire. Turborepo [v2.9.19-canary.5](/release/rel_lOlmgVfR_rD_bnjd-l3a5-turborepo-v2-9-19-canary-5-filters-pruned-pnpm-workspace-patches) filters pruned pnpm workspace patches and fixes caching outputs through internal symlinks, while [v2.9.19-canary.4](/release/rel_vJlYem6yLMz1JTg2O8k8W-turborepo-v2-9-19-canary-4-uses-pty-for-interactive-windows-tasks) brings PTY support for interactive tasks on Windows.","releaseIds":["rel_CAq7HtRGGfAXEZC5mWjTY","rel_ppEEkqbPEwx0ljecbZSOH","rel_liFs5ye75WsPQ_jVd0UXn","rel_J_w4JnZNzRo_sFqAftbK8","rel_F7r2s6feDD7vAEdBgsKWy","rel_sbRGd-c779LX5IYqm4yXx","rel_6Ld0o4EjVViiGKW-Z4-kC","rel_o9nV-woeamWQI_NvWBVwD","rel_KCcdrZScoFhzSaFAkhLn2","rel_1ZbA5lqJMFuE4GnscX1w8","rel_lLpAiqyCos_Vh9lKYJKmA","rel_bL79mjnkL9eO8CZdbBV6Y","rel_CGZeLjNzOHrp6WLDbjOxk","rel_k_P5niuFY9yzwbJJRjOc0","rel_nt-g7A4JHxdR3XTa6KuOO","rel_AMDjhXwgsW8JnVunzbGTz","rel_o0BcprjBN86_ppO-2YEAa","rel_lOlmgVfR_rD_bnjd-l3a5","rel_vJlYem6yLMz1JTg2O8k8W"],"releaseCount":182,"generatedAt":"2026-07-11T16:50:40.134Z","releases":[{"id":"rel_CAq7HtRGGfAXEZC5mWjTY","title":"AI SDK ai@5.0.200 hardens download URL SSRF guard and redacts server errors","path":"/release/rel_CAq7HtRGGfAXEZC5mWjTY-ssrf-guard-hardened-server-errors-redacted-from-ui-streams","org":{"slug":"vercel","name":"Vercel"},"importance":null},{"id":"rel_ppEEkqbPEwx0ljecbZSOH","title":"AI SDK ai@6.0.203 hardens download URL SSRF and redacts server error details","path":"/release/rel_ppEEkqbPEwx0ljecbZSOH-download-url-ssrf-guard-hardened-server-errors-redacted","org":{"slug":"vercel","name":"Vercel"},"importance":null},{"id":"rel_liFs5ye75WsPQ_jVd0UXn","title":"AI SDK ai@7.0.0-canary.172 hardens download URL SSRF guard and redacts errors","path":"/release/rel_liFs5ye75WsPQ_jVd0UXn-ssrf-guard-hardened-server-errors-redacted","org":{"slug":"vercel","name":"Vercel"},"importance":null},{"id":"rel_J_w4JnZNzRo_sFqAftbK8","title":"AI SDK @ai-sdk/fireworks@1.0.41 prevents credential exfiltration","path":"/release/rel_J_w4JnZNzRo_sFqAftbK8-credentials-no-longer-sent-to-arbitrary-urls","org":{"slug":"vercel","name":"Vercel"},"importance":null},{"id":"rel_F7r2s6feDD7vAEdBgsKWy","title":"AI SDK Google provider 3.0.82 prevents prototype pollution and credential exfiltration","path":"/release/rel_F7r2s6feDD7vAEdBgsKWy-prototype-pollution-fixed-credential-exfiltration-prevented","org":{"slug":"vercel","name":"Vercel"},"importance":null},{"id":"rel_sbRGd-c779LX5IYqm4yXx","title":"AI SDK @ai-sdk/mcp@1.0.49 prevents prototype-named tools from bypassing allowlist","path":"/release/rel_sbRGd-c779LX5IYqm4yXx-prototype-named-tools-no-longer-bypass-schemas-allowlist","org":{"slug":"vercel","name":"Vercel"},"importance":null},{"id":"rel_6Ld0o4EjVViiGKW-Z4-kC","title":"AI SDK @ai-sdk/mcp@0.0.19 locks first SSE endpoint and prevents prototype tool bypass","path":"/release/rel_6Ld0o4EjVViiGKW-Z4-kC-first-sse-endpoint-locked-prototype-tool-bypass-prevented","org":{"slug":"vercel","name":"Vercel"},"importance":null},{"id":"rel_o9nV-woeamWQI_NvWBVwD","title":"AI SDK @ai-sdk/gateway@2.0.101 maps forbidden errors to GatewayForbiddenError","path":"/release/rel_o9nV-woeamWQI_NvWBVwD-forbidden-errors-map-to-gatewayforbiddenerror","org":{"slug":"vercel","name":"Vercel"},"importance":null},{"id":"rel_KCcdrZScoFhzSaFAkhLn2","title":"AI SDK Gateway v3.0.131 surfaces provider warnings and maps forbidden errors","path":"/release/rel_KCcdrZScoFhzSaFAkhLn2-provider-warnings-surfaced-forbidden-errors-mapped","org":{"slug":"vercel","name":"Vercel"},"importance":null},{"id":"rel_1ZbA5lqJMFuE4GnscX1w8","title":"AI SDK devtools@0.0.19 fixes secured API access","path":"/release/rel_1ZbA5lqJMFuE4GnscX1w8-devtools-api-access-secured","org":{"slug":"vercel","name":"Vercel"},"importance":null},{"id":"rel_lLpAiqyCos_Vh9lKYJKmA","title":"WAF - WAF Release - 2026-06-15","path":"/release/rel_lLpAiqyCos_Vh9lKYJKmA-waf-waf-release-2026-06-15","org":{"slug":"cloudflare","name":"Cloudflare"},"importance":null},{"id":"rel_bL79mjnkL9eO8CZdbBV6Y","title":"WAF - Use Cloudforce One threat intelligence in WAF rules","path":"/release/rel_bL79mjnkL9eO8CZdbBV6Y-waf-use-cloudforce-one-threat-intelligence-in-waf-rules","org":{"slug":"cloudflare","name":"Cloudflare"},"importance":null},{"id":"rel_CGZeLjNzOHrp6WLDbjOxk","title":"Vercel raises Hobby Blob store limit from 5 to 100","path":"/release/rel_CGZeLjNzOHrp6WLDbjOxk-hobby-blob-stores-5-100","org":{"slug":"vercel","name":"Vercel"},"importance":null},{"id":"rel_k_P5niuFY9yzwbJJRjOc0","title":"Vercel Workflow SDK now runs natively in Nitro v3","path":"/release/rel_k_P5niuFY9yzwbJJRjOc0-workflow-sdk-integrates-natively-with-nitro-v3-dev-server-ui-added","org":{"slug":"vercel","name":"Vercel"},"importance":null},{"id":"rel_nt-g7A4JHxdR3XTa6KuOO","title":"Vercel CLI @vercel/frameworks@3.29.0 adds Bun preset and graduates Eve","path":"/release/rel_nt-g7A4JHxdR3XTa6KuOO-bun-preset-added-eve-framework-graduates-from-experimental","org":{"slug":"vercel","name":"Vercel"},"importance":null},{"id":"rel_AMDjhXwgsW8JnVunzbGTz","title":"Next.js v16.3.0-canary.51 avoids premature Suspense fallback flash","path":"/release/rel_AMDjhXwgsW8JnVunzbGTz-suspense-fallback-flash-avoided-in-dev-render","org":{"slug":"vercel","name":"Vercel"},"importance":null},{"id":"rel_o0BcprjBN86_ppO-2YEAa","title":"Next.js v16.3.0-canary.49 warns on prefetch={true} navigation","path":"/release/rel_o0BcprjBN86_ppO-2YEAa-warn-on-prefetch-true-navigation-without-partial-prefetching","org":{"slug":"vercel","name":"Vercel"},"importance":null},{"id":"rel_lOlmgVfR_rD_bnjd-l3a5","title":"Turborepo v2.9.19-canary.5 filters pruned pnpm workspace patches","path":"/release/rel_lOlmgVfR_rD_bnjd-l3a5-pruned-pnpm-workspace-patches-filtered-symlink-caching-fixed","org":{"slug":"vercel","name":"Vercel"},"importance":null},{"id":"rel_vJlYem6yLMz1JTg2O8k8W","title":"Turborepo v2.9.19-canary.4 uses PTY for interactive Windows tasks","path":"/release/rel_vJlYem6yLMz1JTg2O8k8W-windows-tasks-use-pty-interactively","org":{"slug":"vercel","name":"Vercel"},"importance":null}]}}