CVE-2025-32421A low severity cache poisoning vulnerability was discovered in Next.js. This affects versions 14.2.9 through <15.1.6 as a bypass of the previous CVE-2024-46982.Ty SbanoChief Information Security Officer
Protection against React Router vulnerability CVE-2025-31137Research in the Remix web framework revealed a vulnerability in React router. Investigations determined that Vercel and customers are unaffected.Casey GowrieSoftware Engineer
Lower pricing for Fast Data TransferLower the price of Fast Data Transfer (FDT) for Vercel regions in Asia Pacific, Latin America, and Africa by up to 50%. Harpreet Arora, Malavika Tadeusz, and 1 other
Enhanced Builds now have double the computeEnterprise customers using Enhanced Build Machines now benefit from 8 of our faster CPUs. This upgrade is available today and has delivered an average 20 percent improvement in build performance across high-volume projects.Andrew Healey , Marc Codina Segura, and 1 other
Vercel Observability is now route-aware for SvelteKit appsImproved route-level visibility to Vercel Observability for SvelteKit projects using @sveltejs/adapter-vercel v5.7.0. Dynamic segments like /blog/[slug] now appear as individual routes.Tobias Lins, Rich Harris
Legacy build image is being deprecated on September 1, 2025The legacy build image will be deprecated on September 1, 2025, alongside the deprecation of Node.js 18.Anthony Shew, Ali Smesseim
Grok 3 now available on Vercel MarketplaceGrok 3 is now available on the Vercel Marketplace, allowing users to access xAI's latest large language models directly from their Vercel projects+6Hedi Zandi, Dima Voytenko, and 6 others
Automatic mitigation of Google and Bing crawl delay, via Vercel’s Skew ProtectionThe maximum age for Skew Protection is now extended to 60 days for requests coming from web crawlers such as Googlebot or Bingbot.Steven Salat, Malte Ubl