CVE-2026-44907

Summary

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.7, 19.1.0 through 19.1.8, and 19.2.0 through 19.2.7).

Affected Software

VendorProductVersion RangeStatus
Metareact-server-dom-turbopack19.0.0 <= 19.0.7affected
Metareact-server-dom-turbopack19.1.0 <= 19.1.8affected
Metareact-server-dom-turbopack19.2.0 <= 19.2.7affected
Metareact-server-dom-parcel19.0.0 <= 19.0.7affected
Metareact-server-dom-parcel19.1.0 <= 19.1.8affected
Metareact-server-dom-parcel19.2.0 <= 19.2.7affected
Metareact-server-dom-webpack19.0.0 <= 19.0.7affected
Metareact-server-dom-webpack19.1.0 <= 19.1.8affected
Metareact-server-dom-webpack19.2.0 <= 19.2.7affected

Weaknesses

  • CWE-502, CWE-400

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References