Top
Best
New

Posted by colesantiago 16 hours ago

Vercel April 2026 security incident(www.bleepingcomputer.com)
https://vercel.com/kb/bulletin/vercel-april-2026-security-in...
622 points | 350 commentspage 4
gneray 15 hours ago|
Oy vey: https://x.com/theo/status/2045862972342313374?s=46
rubiquity 15 hours ago|
He doesn't work at Vercel but he is the type to never pass up any opportunity to chase clout.
dankwizard 5 hours ago|||
He is affiliated with Vercel though
threecheese 14 hours ago|||
Almost like that’s his job.

Hey, I’m with you - I think social media needs to die specifically for this reason. I’m reminded of the term “snake oil” - it’s like the dawn of newspapers again.

TiredOfLife 11 hours ago||
Media as a whole needs to die
hoppyhoppy2 7 hours ago||
Including books and the internet?
ofabioroma 15 hours ago||
Time to ipo
ebbi 11 hours ago||
Ahhh...another product I'm boycotting, and now doubly glad I'm boycotting.
OsamaJaber 12 hours ago||
That's why infra needs stricter internal walls than normal SaaS
_puk 13 hours ago||
Hmmm, the dashboard 404 I got 6 hours ago now makes a bit more sense..
jheitzeb 13 hours ago||
Missing from Glasswing
0xy 15 hours ago||
This is why you pay a real provider for serious business needs, not an AWS reseller. Next.js is a fundamentally insecure framework, as server components are an anti-pattern full of magic leading to stuff like the below. Given their standards for framework security, it's not hard to believe their business' control plane is just as insecure (and probably built using the same insecure framework).

Next.js is the new PHP, but worse, since unlike PHP you don't really know what's server side and what's client side anymore. It's all just commingled and handled magically.

https://aws.amazon.com/security/security-bulletins/rss/aws-2...

embedding-shape 15 hours ago||
> Next.js is the new PHP, but worse, since unlike PHP you don't really know what's server side and what's client side anymore. It's all just commingled and handled magically.

Wasn't unheard of back in the day, that you leaked things via PHP templates, like serializing and adding the whole user object including private details in a Twig template or whatever, it just happened the other way around kind of. This was before "fat frontend, thin backend" was the prevalent architecture, many built their "frontends" from templates with just sprinkles of JavaScript back then.

sbarre 15 hours ago|||
People say "Next.js is the new PHP" because it's the most popular and prominent tooling out there, and so by sheer number of available targets it's the one that comes up the most when things go wrong like this.

But there are more people trying to secure this framework and the underlying tools than there would be on some obscure framework or something the average company built themselves.

Also "pay a real provider", what does that mean? Are you again implying that the average company should be responsible for _more_ of their own security in their hosting stack, not less?

Most companies have _zero_ security engineers.. Using a vertically-integrated hosting company like Vercel (or other similar companies, perhaps with different tech stacks - this opinion has nothing to do with Next or Node) is very likely their best and most secure option based on what they are able to invest in that area.

bakugo 14 hours ago||
Next.js is the polar opposite of PHP, in a way.

PHP was so simple and easy to understand that anyone with a text editor and some cheap shared hosting could pick it up, but also low level enough that almost nothing was magically done for you. The result was many inexperienced developers making really basic mistakes while implementing essential features that we now take for granted.

Frameworks like Next.js take the complete opposite approach, they are insanely complex but hide that complexity behind layers and layers of magic, actively discouraging developers from looking behind the curtain, and the result is that even experienced developers end up shooting themselves in the foot by using the magical incantations wrong.

qudat 13 hours ago||
Totally agree. Nextjs is a vehicle to sell their PaaS, every other feature is a coincidence.

What’s worse is vercel corrupted the react devs and convinced them that RSC was a good idea. It’s not like react was strictly in good hands at Facebook but at least the team there were good shepherds and trying to foster the ecosystem.

jamesfisher 10 hours ago||
Reminder the Vercel CEO is a genocide supporter, if you need more reasons to move away from it.
gib444 10 hours ago|
You forgot the source to backup your claim
ascorbic 9 hours ago|||
https://x.com/rauchg/status/1972669025525158031
jofzar 4 hours ago||
Oof
jeromegv 3 hours ago|||
https://techforpalestine.org/vercel
monirmamoun 10 hours ago||
[flagged]
jeromegv 3 hours ago|
I knew from that moment never to use any Vercel product. If your leadership is that compromised, you know the rest of the ship is heading into a wall.
nothinkjustai 13 hours ago|
Looks like their rampant vibe coding is starting to catch up to them. Expect to see many pre vulns like this in the future.
More comments...