React Server Components Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability exists in the React Server Components packages: react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack. This vulnerability affects versions 19.0.0 through 19.0.5, 19.1.0 through 19.1.6, and 19.2.0 through 19.2.5. The issue can be triggered by sending specially crafted HTTP requests to server function endpoints, leading to server crashes, out-of-memory exceptions, or excessive CPU usage.

Impact

Exploitation of this vulnerability can cause server crashes, out-of-memory exceptions, or excessive CPU usage.

Remediation

Users are advised to upgrade to react-server-dom-webpack, react-server-dom-parcel, or react-server-dom-turbopack versions 19.0.6, 19.1.7, or 19.2.6.

Added: May 6, 2026, 8:57 PM
Updated: May 6, 2026, 8:57 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
7.6
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.