React-Server-Dom-Webpack
Meta · 8 CVEs
A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endp…
Jul 21, 2026
react-server-dom-webpack: react-server-dom-parcel: react-server-dom-turbopack: React Server DOM: Denial of Service via…
May 6, 2026
react-server-dom-parcel: react-server-dom-turbopack: react-server-dom-webpack: denial of service via specially crafted…
Apr 8, 2026
react-server-dom-webpack: react-server-dom-parcel: reactreact-server-dom-turbopack: React Server Components: Denial of…
Jan 26, 2026
next: React Server Components: Denial of Service via Unsafe Deserialization
Dec 11, 2025
next: React Server Components: Denial of Service via unsafe HTTP deserialization
Dec 11, 2025
next: React Server Components: Source code exposure through crafted HTTP request
Dec 11, 2025
next: React Server Components: Pre-authentication remote code execution via unsafe deserialization
Dec 3, 2025
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-44907 | A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU… | HIGH | 0.60% | Jul 21, 2026 |
| CVE-2026-23870 | react-server-dom-webpack: react-server-dom-parcel: react-server-dom-turbopack: React Server DOM: Denial of Service via specially crafted HTTP requests | HIGH | 1.53% | May 6, 2026 |
| CVE-2026-23869 | react-server-dom-parcel: react-server-dom-turbopack: react-server-dom-webpack: denial of service via specially crafted HTTP requests to Server Function endpoin… | HIGH | 1.55% | Apr 8, 2026 |
| CVE-2026-23864 | react-server-dom-webpack: react-server-dom-parcel: reactreact-server-dom-turbopack: React Server Components: Denial of Service via specially crafted HTTP reque… | HIGH | 2.58% | Jan 26, 2026 |
| CVE-2025-67779 | next: React Server Components: Denial of Service via Unsafe Deserialization | HIGH | 19.99% | Dec 11, 2025 |
| CVE-2025-55184 | next: React Server Components: Denial of Service via unsafe HTTP deserialization | HIGH | 66.88% | Dec 11, 2025 |
| CVE-2025-55183 | next: React Server Components: Source code exposure through crafted HTTP request | MEDIUM | 64.23% | Dec 11, 2025 |
| CVE-2025-55182 KEV | next: React Server Components: Pre-authentication remote code execution via unsafe deserialization | CRITICAL | 99.80% | Dec 3, 2025 |
Showing 1 to 8 of 8 CVEs