A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.7, 19.1.0 through 19.1.8, and 19.2.0 through 19.2.7).
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Meta | React-Server-Dom-Parcel | >= 19.0.0, <= 19.0.7, >= 19.1.0, <= 19.1.8, >= 19.2.0, <= 19.2.7CNA affecteddefault unaffected | |
| Meta | React-Server-Dom-Turbopack | >= 19.0.0, <= 19.0.7, >= 19.1.0, <= 19.1.8, >= 19.2.0, <= 19.2.7CNA affecteddefault unaffected | |
| Meta | React-Server-Dom-Webpack | >= 19.0.0, <= 19.0.7, >= 19.1.0, <= 19.1.8, >= 19.2.0, <= 19.2.7CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.