Denial of Service Vulnerability in React Server Packages by React
CVE-2026-44907
7.5HIGH
What is CVE-2026-44907?
A denial of service vulnerability exists in the React Server Packages, allowing attackers to create specially crafted HTTP requests that can lead to excessive CPU utilization. This may severely degrade the performance of the application, potentially resulting in service interruptions or outages. Affected packages include react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack across several version ranges. It is recommended to assess the impact on your environment and apply security patches where necessary.
Affected Version(s)
react-server-dom-parcel 19.0.0 <= 19.0.7
react-server-dom-parcel 19.1.0 <= 19.1.8
react-server-dom-parcel 19.2.0 <= 19.2.7
