Denial of Service Vulnerability in React Server Packages by React
CVE-2026-44907

7.5HIGH

What is CVE-2026-44907?

A denial of service vulnerability exists in the React Server Packages, allowing attackers to create specially crafted HTTP requests that can lead to excessive CPU utilization. This may severely degrade the performance of the application, potentially resulting in service interruptions or outages. Affected packages include react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack across several version ranges. It is recommended to assess the impact on your environment and apply security patches where necessary.

Affected Version(s)

react-server-dom-parcel 19.0.0 <= 19.0.7

react-server-dom-parcel 19.1.0 <= 19.1.8

react-server-dom-parcel 19.2.0 <= 19.2.7

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.