CVE-2026-23870
published 2026-05-06CVE-2026-23870: A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server…
high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.5, 19.1.0 through 19.1.6, and 19.2.0 through 19.2.5).
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| meta | react-server-dom-parcel | >= 19.0.0 < 19.0.6 | 19.0.6 |
| meta | react-server-dom-parcel | 19.0.0 – 19.0.5 | — |
| meta | react-server-dom-parcel | >= 19.1.0 < 19.1.7 | 19.1.7 |
| meta | react-server-dom-parcel | 19.1.0 – 19.1.6 | — |
| meta | react-server-dom-parcel | >= 19.2.0 < 19.2.6 | 19.2.6 |
| meta | react-server-dom-parcel | 19.2.0 – 19.2.5 | — |
| meta | react-server-dom-turbopack | >= 19.0.0 < 19.0.6 | 19.0.6 |
| meta | react-server-dom-turbopack | 19.0.0 – 19.0.5 | — |
| meta | react-server-dom-turbopack | >= 19.1.0 < 19.1.7 | 19.1.7 |
| meta | react-server-dom-turbopack | 19.1.0 – 19.1.6 | — |
| meta | react-server-dom-turbopack | >= 19.2.0 < 19.2.6 | 19.2.6 |
| meta | react-server-dom-turbopack | 19.2.0 – 19.2.5 | — |
| meta | react-server-dom-webpack | >= 19.0.0 < 19.0.6 | 19.0.6 |
| meta | react-server-dom-webpack | 19.0.0 – 19.0.5 | — |
| meta | react-server-dom-webpack | >= 19.1.0 < 19.1.7 | 19.1.7 |
| meta | react-server-dom-webpack | 19.1.0 – 19.1.6 | — |
| meta | react-server-dom-webpack | >= 19.2.0 < 19.2.6 | 19.2.6 |
| meta | react-server-dom-webpack | 19.2.0 – 19.2.5 | — |
| next | next | >= 13.0.0 < 15.5.16 | 15.5.16 |
| next | next | >= 16.0.0 < 16.2.5 | 16.2.5 |
| rhoai | odh-dashboard-rhel9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa7.5HIGH