We found results for “”
CVE-2026-23864
Good to know:
Date: January 26, 2026
Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending specially crafted HTTP requests to Server Function endpoints, and could lead to server crashes, out-of-memory exceptions or excessive CPU usage; depending on the vulnerable code path being exercised, the application configuration and application code. Strongly consider upgrading to the latest package versions to reduce risk and prevent availability issues in applications using React Server Components.
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Top Fix
Upgrade Version
Upgrade to version react-server-dom-webpack - 19.0.4;react-server-dom-webpack - 19.1.5;react-server-dom-webpack - 19.2.4;react-server-dom-webpack - 19.2.4;react-server-dom-webpack - 19.1.5;react-server-dom-turbopack - 19.0.4;react-server-dom-turbopack - 19.1.5;react-server-dom-turbopack - 19.2.4;react-server-dom-turbopack - 19.1.5;react-server-dom-turbopack - 19.2.4;react-server-dom-parcel - 19.0.4;react-server-dom-parcel - 19.1.5;react-server-dom-parcel - 19.2.4;react-server-dom-parcel - 19.1.5;react-server-dom-parcel - 19.2.4
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | NONE |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


