← Back

CVE-2026-23870

nvd nist
Published: May 6, 2026Modified: Aug 12, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: cve-assign@fb.com (Secondary)

Description

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.5, 19.1.0 through 19.1.6, and 19.2.0 through 19.2.5).

Affected (9)

3 products
React Server Dom Parcel
React Server Dom Turbopack
React Server Dom Webpack
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Facebook
From 19.0.0 to 19.0.5
From 19.1.0 to 19.1.6
From 19.2.0 to 19.2.5
Facebook
From 19.0.0 to 19.0.5
From 19.1.0 to 19.1.6
From 19.2.0 to 19.2.5
Facebook
From 19.0.0 to 19.0.5
From 19.1.0 to 19.1.6
From 19.2.0 to 19.2.5

References (1)

Timeline

No history available yet.