Skip to content

Update npm package @ai-sdk/provider-utils to v4.0.33 [SECURITY] - #440

Open
hash-dependencies[bot] wants to merge 1 commit into
mainfrom
deps/js/npm-ai-sdk-provider-utils-vulnerability
Open

hash-dependencies[bot] wants to merge 1 commit into
mainfrom
deps/js/npm-ai-sdk-provider-utils-vulnerability

Conversation

@hash-dependencies

@hash-dependencies hash-dependencies Bot commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@ai-sdk/provider-utils (source) 4.0.21 → 4.0.33 age confidence

@​ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue

CVE-2026-8769 / GHSA-866g-f22w-33x8

More information

Details

Versions of @ai-sdk/provider-utils before 3.0.28, from 4.0.0 before 4.0.33, and from 5.0.0 before 5.0.1 are vulnerable to uncontrolled resource consumption. The createJsonResponseHandler, createJsonErrorResponseHandler, and createStatusCodeErrorResponseHandler functions in packages/provider-utils/src/response-handler.ts read response bodies without a shared size limit, allowing a remote attacker with low privileges to cause excessive memory consumption. The exploit has been publicly disclosed and may be utilized.

Severity

  • CVSS Score: 2.1 / 10 (Low)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

vercel/ai (@​ai-sdk/provider-utils)

v4.0.33

Compare Source

Patch Changes
  • b30e43a: Limit JSON response body reads in response handlers to prevent unbounded memory use.

v4.0.32

Compare Source

Patch Changes

v4.0.31

Patch Changes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • "before 4am every weekday,every weekend"

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@cursor

cursor Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
Security dependency patch for AI SDK HTTP response handling; risk is limited to lockfile resolution, but nested @ai-sdk/react may still pull the pre-patch provider-utils version.

Overview
Lockfile-only update that resolves @ai-sdk/provider-utils from 4.0.21 to 4.0.33, addressing CVE-2026-8769 (unbounded reads of HTTP response bodies in JSON/status error handlers, which could drive excessive memory use).

The bump also refreshes related locked versions (@ai-sdk/provider 3.0.12, eventsource-parser 3.1.1). There is no application source change—only package-lock.json. Note that @ai-sdk/react still nests @ai-sdk/provider-utils@4.0.21 in the lockfile, so some code paths may keep using the older copy until that dependency tree is updated separately.

Reviewed by Cursor Bugbot for commit a4f1498. Bugbot is set up for automated code reviews on this repo. Configure here.

@hash-dependencies
hash-dependencies Bot force-pushed the deps/js/npm-ai-sdk-provider-utils-vulnerability branch from 090de48 to a4f1498 Compare September 27, 2026 03:15

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants