---
collection: application-platforms
collection_name: Application Platforms
week_start: 2026-06-08
title: Security hardening week across the AI SDK and Workers edge
release_count: 182
generated: 2026-07-11
canonical: https://releases.sh/collections/application-platforms/digest/2026-06-08
---

# Security hardening week across the AI SDK and Workers edge

Vercel's AI SDK received coordinated security patches for SSRF, credential exfiltration, and prototype pollution vulnerabilities across a dozen provider packages, while Cloudflare shipped new WAF rules for Ghost CMS SQL injection and threat intelligence integration.

### Security patches sweep the AI SDK

This week's dominant story is a coordinated security release across the Vercel AI SDK. Multiple vulnerabilities were identified and patched in a single day, affecting the core runtime and nearly every provider adapter.

The most critical fix addresses a Server-Side Request Forgery (SSRF) vulnerability in the download URL validation. The `validateDownloadUrl` function and the `downloadBlob`/`download` helpers were found to be bypassable in several ways: a fully-qualified hostname with a trailing dot (e.g., `localhost.`) skipped the localhost blocklist, IPv6 addresses embedding an IPv4 address in their last 32 bits could bypass detection, and the `validateDownloadUrl` guard wasn't applied to redirect targets. This was fixed across three major versions: [ai@5.0.200](/release/rel_CAq7HtRGGfAXEZC5mWjTY-ai-sdk-ai-5-0-200-hardens-download-url-ssrf-guard-and-redacts-server-errors), [ai@6.0.203](/release/rel_ppEEkqbPEwx0ljecbZSOH-ai-sdk-ai-6-0-203-hardens-download-url-ssrf-and-redacts-server-error-details), and the canary branch [ai@7.0.0-canary.172](/release/rel_liFs5ye75WsPQ_jVd0UXn-ai-sdk-ai-7-0-0-canary-172-hardens-download-url-ssrf-guard-and-redacts-errors), the latter of which also removed deprecated experimental `generateImage` exports.

A second class of vulnerability involved credential exfiltration. Several provider clients would follow a URL returned by the provider's API response (for polling, status, or media URLs) and reuse the authenticated headers — or append `?key=<API_KEY>` — on that request. Because the host of the response-supplied URL was never validated, an attacker who controlled that URL could capture the API key. This was patched across the [Fireworks](/release/rel_J_w4JnZNzRo_sFqAftbK8-ai-sdk-ai-sdk-fireworks-1-0-41-prevents-credential-exfiltration) and [Google](/release/rel_F7r2s6feDD7vAEdBgsKWy-ai-sdk-google-provider-3-0-82-prevents-prototype-pollution-and-credential) providers, with the Google fix also addressing prototype pollution when streaming tool arguments.

The MCP client saw two patches: prototype-named tools like `constructor` or `__proto__` could bypass the `schemas` allowlist because the check used the `in` operator instead of `Object.hasOwn` — fixed in [@ai-sdk/mcp@1.0.49](/release/rel_sbRGd-c779LX5IYqm4yXx-ai-sdk-ai-sdk-mcp-1-0-49-prevents-prototype-named-tools-from-bypassing-allowlist) and [@ai-sdk/mcp@0.0.19](/release/rel_6Ld0o4EjVViiGKW-Z4-kC-ai-sdk-ai-sdk-mcp-0-0-19-locks-first-sse-endpoint-and-prevents-prototype-tool). Both also locked the first SSE endpoint received via event to prevent endpoint switching. The AI Gateway followed with [@ai-sdk/gateway@2.0.101](/release/rel_o9nV-woeamWQI_NvWBVwD-ai-sdk-ai-sdk-gateway-2-0-101-maps-forbidden-errors-to-gatewayforbiddenerror) and [Gateway v3.0.131](/release/rel_KCcdrZScoFhzSaFAkhLn2-ai-sdk-gateway-v3-0-131-surfaces-provider-warnings-and-maps-forbidden-errors) mapping forbidden errors to `GatewayForbiddenError` instead of `GatewayInternalServerError`, the latter also surfacing provider warnings in embedding and reranking responses. Finally, [AI SDK devtools@0.0.19](/release/rel_1ZbA5lqJMFuE4GnscX1w8-ai-sdk-devtools-0-0-19-fixes-secured-api-access) secured the devtools viewer API access.

### Cloudflare edge security: WAF rules and threat intelligence

On the Cloudflare side, the Application Security team shipped two significant WAF releases. The [WAF release of 2026-06-15](/release/rel_lLpAiqyCos_Vh9lKYJKmA-waf-waf-release-2026-06-15) introduced new managed protection for a critical SQL injection vulnerability in Ghost CMS (CVE-2026-26980) and a generic rule targeting sophisticated SQLi bypass attempts using obfuscated boolean logic — both deployed at the network edge before traffic reaches the origin.

More strategically, Cloudflare now lets you [match WAF rules against Cloudforce One threat intelligence](/release/rel_bL79mjnkL9eO8CZdbBV6Y-waf-use-cloudforce-one-threat-intelligence-in-waf-rules). A new detection looks up each request's client IP against the threat intelligence database. If the IP was involved in threat activity in the past seven days, Cloudflare populates `cf.intel.ip.*` fields that you can use in custom rules and rate limiting rules. This brings real-time threat data directly into the WAF rule engine, a significant upgrade for teams that need to block known bad actors without maintaining their own IP blocklists.

### Vercel platform: Blob limits, Workflow in Nitro, and CLI improvements

Vercel raised the [Hobby Blob store limit from 5 to 100](/release/rel_CGZeLjNzOHrp6WLDbjOxk-vercel-raises-hobby-blob-store-limit-from-5-to-100), giving hobby-tier teams the flexibility to organize data by project, environment, or region without hitting artificial constraints. Storage, operations, and transfer limits still apply, but the 20x increase removes a common friction point for growing applications.

The [Vercel Workflow SDK now runs natively in Nitro v3](/release/rel_k_P5niuFY9yzwbJJRjOc0-vercel-workflow-sdk-now-runs-natively-in-nitro-v3) in beta. Steps run inside the same bundled runtime as the rest of your app, letting you use Nitro's `useStorage()` and other server-side APIs directly inside `"use step"` functions. The dev server also serves a workflow web UI at `/_workflow` for inspecting, monitoring, and debugging runs. Workflow routes are now bundled by Nitro with dependency tracing and tree-shaking, promising faster builds and smaller bundles.

The Vercel CLI saw user-facing improvements: `vercel@54.13.0` added a `--category` filter to `vercel integration discover` and a new `vercel integration categories` subcommand, while `vercel@54.14.0` introduced `ai-gateway rules` commands for adding, listing, editing, and removing rules. The [@vercel/frameworks@3.29.0](/release/rel_nt-g7A4JHxdR3XTa6KuOO-vercel-cli-vercel-frameworks-3-29-0-adds-bun-preset-and-graduates-eve) package graduated the Eve framework from experimental and added a Bun preset.

### Next.js canary and Turborepo fixes

The [Next.js v16.3.0-canary.51](/release/rel_AMDjhXwgsW8JnVunzbGTz-next-js-v16-3-0-canary-51-avoids-premature-suspense-fallback-flash) avoids a premature Suspense fallback flash in the streaming dev render, while [v16.3.0-canary.49](/release/rel_o0BcprjBN86_ppO-2YEAa-next-js-v16-3-0-canary-49-warns-on-prefetch-true-navigation) adds a warning for `prefetch={true}` navigation when Partial Prefetching is not enabled, and serves stale `'use cache'` entries until they expire. Turborepo [v2.9.19-canary.5](/release/rel_lOlmgVfR_rD_bnjd-l3a5-turborepo-v2-9-19-canary-5-filters-pruned-pnpm-workspace-patches) filters pruned pnpm workspace patches and fixes caching outputs through internal symlinks, while [v2.9.19-canary.4](/release/rel_vJlYem6yLMz1JTg2O8k8W-turborepo-v2-9-19-canary-4-uses-pty-for-interactive-windows-tasks) brings PTY support for interactive tasks on Windows.

## Releases covered

### Cloudflare

- [WAF - WAF Release - 2026-06-15](https://releases.sh/release/rel_lLpAiqyCos_Vh9lKYJKmA-waf-waf-release-2026-06-15)
- [WAF - Use Cloudforce One threat intelligence in WAF rules](https://releases.sh/release/rel_bL79mjnkL9eO8CZdbBV6Y-waf-use-cloudforce-one-threat-intelligence-in-waf-rules)

### Vercel

- [AI SDK ai@5.0.200 hardens download URL SSRF guard and redacts server errors](https://releases.sh/release/rel_CAq7HtRGGfAXEZC5mWjTY-ssrf-guard-hardened-server-errors-redacted-from-ui-streams)
- [AI SDK ai@6.0.203 hardens download URL SSRF and redacts server error details](https://releases.sh/release/rel_ppEEkqbPEwx0ljecbZSOH-download-url-ssrf-guard-hardened-server-errors-redacted)
- [AI SDK ai@7.0.0-canary.172 hardens download URL SSRF guard and redacts errors](https://releases.sh/release/rel_liFs5ye75WsPQ_jVd0UXn-ssrf-guard-hardened-server-errors-redacted)
- [AI SDK @ai-sdk/fireworks@1.0.41 prevents credential exfiltration](https://releases.sh/release/rel_J_w4JnZNzRo_sFqAftbK8-credentials-no-longer-sent-to-arbitrary-urls)
- [AI SDK Google provider 3.0.82 prevents prototype pollution and credential exfiltration](https://releases.sh/release/rel_F7r2s6feDD7vAEdBgsKWy-prototype-pollution-fixed-credential-exfiltration-prevented)
- [AI SDK @ai-sdk/mcp@1.0.49 prevents prototype-named tools from bypassing allowlist](https://releases.sh/release/rel_sbRGd-c779LX5IYqm4yXx-prototype-named-tools-no-longer-bypass-schemas-allowlist)
- [AI SDK @ai-sdk/mcp@0.0.19 locks first SSE endpoint and prevents prototype tool bypass](https://releases.sh/release/rel_6Ld0o4EjVViiGKW-Z4-kC-first-sse-endpoint-locked-prototype-tool-bypass-prevented)
- [AI SDK @ai-sdk/gateway@2.0.101 maps forbidden errors to GatewayForbiddenError](https://releases.sh/release/rel_o9nV-woeamWQI_NvWBVwD-forbidden-errors-map-to-gatewayforbiddenerror)
- [AI SDK Gateway v3.0.131 surfaces provider warnings and maps forbidden errors](https://releases.sh/release/rel_KCcdrZScoFhzSaFAkhLn2-provider-warnings-surfaced-forbidden-errors-mapped)
- [AI SDK devtools@0.0.19 fixes secured API access](https://releases.sh/release/rel_1ZbA5lqJMFuE4GnscX1w8-devtools-api-access-secured)
- [Vercel raises Hobby Blob store limit from 5 to 100](https://releases.sh/release/rel_CGZeLjNzOHrp6WLDbjOxk-hobby-blob-stores-5-100)
- [Vercel Workflow SDK now runs natively in Nitro v3](https://releases.sh/release/rel_k_P5niuFY9yzwbJJRjOc0-workflow-sdk-integrates-natively-with-nitro-v3-dev-server-ui-added)
- [Vercel CLI @vercel/frameworks@3.29.0 adds Bun preset and graduates Eve](https://releases.sh/release/rel_nt-g7A4JHxdR3XTa6KuOO-bun-preset-added-eve-framework-graduates-from-experimental)
- [Next.js v16.3.0-canary.51 avoids premature Suspense fallback flash](https://releases.sh/release/rel_AMDjhXwgsW8JnVunzbGTz-suspense-fallback-flash-avoided-in-dev-render)
- [Next.js v16.3.0-canary.49 warns on prefetch={true} navigation](https://releases.sh/release/rel_o0BcprjBN86_ppO-2YEAa-warn-on-prefetch-true-navigation-without-partial-prefetching)
- [Turborepo v2.9.19-canary.5 filters pruned pnpm workspace patches](https://releases.sh/release/rel_lOlmgVfR_rD_bnjd-l3a5-pruned-pnpm-workspace-patches-filtered-symlink-caching-fixed)
- [Turborepo v2.9.19-canary.4 uses PTY for interactive Windows tasks](https://releases.sh/release/rel_vJlYem6yLMz1JTg2O8k8W-windows-tasks-use-pty-interactively)
