CVE-2026-44907
Received Received - Intake

Denial of Service in React Server DOM Packages

Vulnerability report for CVE-2026-44907, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-07-21

Assigner: Facebook, Inc.

Description

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.7, 19.1.0 through 19.1.8, and 19.2.0 through 19.2.7).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-07-21
Generated
2026-07-21
AI Q&A
2026-07-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 18 associated CPEs
Vendor Product Version / Range
facebook react-server-dom-webpack From 19.0.0 (inc) to 19.0.7 (inc)
facebook react-server-dom-parcel From 19.0.0 (inc) to 19.0.7 (inc)
facebook react-server-dom-turbopack From 19.0.0 (inc) to 19.0.7 (inc)
facebook react-server-dom-webpack From 19.1.0 (inc) to 19.1.8 (inc)
facebook react-server-dom-parcel From 19.1.0 (inc) to 19.1.8 (inc)
facebook react-server-dom-turbopack From 19.1.0 (inc) to 19.1.8 (inc)
facebook react-server-dom-webpack From 19.2.0 (inc) to 19.2.7 (inc)
facebook react-server-dom-parcel From 19.2.0 (inc) to 19.2.7 (inc)
facebook react-server-dom-turbopack From 19.2.0 (inc) to 19.2.7 (inc)
facebook react_server_dom_webpack From 19.0.0 (inc) to 19.0.7 (inc)
facebook react_server_dom_parcel From 19.0.0 (inc) to 19.0.7 (inc)
facebook react_server_dom_turbopack From 19.0.0 (inc) to 19.0.7 (inc)
facebook react_server_dom_webpack From 19.1.0 (inc) to 19.1.8 (inc)
facebook react_server_dom_parcel From 19.1.0 (inc) to 19.1.8 (inc)
facebook react_server_dom_turbopack From 19.1.0 (inc) to 19.1.8 (inc)
facebook react_server_dom_webpack From 19.2.0 (inc) to 19.2.7 (inc)
facebook react_server_dom_parcel From 19.2.0 (inc) to 19.2.7 (inc)
facebook react_server_dom_turbopack From 19.2.0 (inc) to 19.2.7 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a denial of service vulnerability in React Server Components packages (react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack). Attackers can send specially crafted HTTP requests to server function endpoints, causing excessive CPU usage or out-of-memory exceptions. The vulnerability affects versions 19.0.0 through 19.0.7, 19.1.0 through 19.1.8, and 19.2.0 through 19.2.7.

Detection Guidance

To detect this vulnerability, check if your system is running affected versions of react-server-dom-webpack, react-server-dom-parcel, or react-server-dom-turbopack (19.0.0-19.0.7, 19.1.0-19.1.8, 19.2.0-19.2.7). Use commands like 'npm list react-server-dom-webpack' or 'yarn list react-server-dom-webpack' to verify installed versions.

Impact Analysis

This vulnerability can lead to system unavailability due to excessive CPU usage or crashes from out-of-memory errors. It does not require privileges or user interaction to exploit, making it easier for attackers to disrupt services. Applications not using React Server Components or server functions are unaffected.

Compliance Impact

This vulnerability primarily impacts system availability by causing excessive CPU usage or out-of-memory exceptions through crafted HTTP requests. While it does not directly expose data, prolonged unavailability could lead to violations of availability requirements in GDPR (Article 32) and HIPAA (Security Rule Β§164.312). Organizations must ensure timely patching to maintain compliance with these standards.

Mitigation Strategies

Immediately update affected packages to versions 19.0.8, 19.1.9, or 19.2.8 or later. If updating is not possible, consider disabling React Server Components or server functions if they are not essential to your application.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-44907. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart