Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-23864

34
FAUCET Score

CVE-2026-23864 describes multiple denial of service vulnerabilities in React Server Components, specifically impacting react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. These vulnerabilities, rated High with a CVSS score of 7.5, can be triggered by unauthenticated, specially crafted HTTP requests, leading to server crashes, out-of-memory errors, or high CPU usage. While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered some community discussion and media coverage, indicating awareness. Organizations using affected React Server Components should prioritize upgrading to the latest versions to mitigate this availability risk.

Impacted Technologies

VendorProductVersion(s)CPE
>= 19.0.0, < 19.0.4CPE matchmatch criteria
cpe:2.3:a:facebook:react:*:*:*:*:*:*:*:*
>= 19.1.0, < 19.1.5CPE matchmatch criteria
cpe:2.3:a:facebook:react:*:*:*:*:*:*:*:*
>= 19.2.0, < 19.2.4CPE matchmatch criteria
cpe:2.3:a:facebook:react:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.39%
Probability of exploitation in next 30 days
EPSS Percentile
82.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0239 is in the 68th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

npmpatch availablevia ghsa
Product: react-server-dom-parcelFixed in: 19.0.4
npmpatch availablevia ghsa
Product: react-server-dom-turbopackFixed in: 19.1.5
npmpatch availablevia ghsa
Product: react-server-dom-webpackFixed in: 19.2.4
npmpatch availablevia ghsa
Product: react-server-dom-turbopackFixed in: 19.0.4
npmpatch availablevia ghsa
Product: react-server-dom-parcelFixed in: 19.1.5
npmpatch availablevia ghsa
Product: react-server-dom-parcelFixed in: 19.2.4
npmpatch availablevia ghsa
Product: react-server-dom-webpackFixed in: 19.1.5
npmpatch availablevia ghsa
Product: react-server-dom-webpackFixed in: 19.0.4
npmpatch availablevia ghsa
Product: react-server-dom-turbopackFixed in: 19.2.4

Vendor Advisories (1)

npmGHSA-83fc-fqcc-2hmghigh

React Server Components have multiple Denial of Service Vulnerabilities

Jan 29, 2026

References

access.redhat.com / errata/RHSA-2026:13571
access.redhat.com / errata/RHSA-2026:34608
access.redhat.com / security/cve/CVE-2026-23864
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-23864.json
facebook.com / security/advisories/cve-2026-23864
Vendor Advisory