The number and severity of CVEs published that impact products developed by Redwoodjs over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-39371HIGH RedwoodSDK is a server-first React framework. From 1.0.0-beta.50 to 1.0.5, erver functions exported from "use server" files could be invoked via GET requests, bypassing their inten | Apr 7, 2026 | 8.1 | 27 | NO | NO |
CVE-2026-42190MEDIUM RedwoodSDK is a server-first React framework. From version 1.0.0-beta.50 to before version 1.2.3, server actions in rwsdk apply HTTP method enforcement but no origin validation. A | May 8, 2026 | 5.3 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Redwoodjs.
Media articles that mention a CVE ID that affects a product developed by Redwoodjs — matched by CVE ID, not by vendor name.