High severityNVD Advisory· Published Jul 21, 2026· Updated Jul 21, 2026
CVE-2026-44907
CVE-2026-44907
Description
A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.7, 19.1.0 through 19.1.8, and 19.2.0 through 19.2.7).
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
react-server-dom-webpacknpm | >= 19.0.0, < 19.0.8 | 19.0.8 |
react-server-dom-turbopacknpm | >= 19.0.0, < 19.0.8 | 19.0.8 |
react-server-dom-turbopacknpm | >= 19.1.0, < 19.1.9 | 19.1.9 |
react-server-dom-parcelnpm | >= 19.1.0, < 19.1.9 | 19.1.9 |
react-server-dom-webpacknpm | >= 19.1.0, < 19.1.9 | 19.1.9 |
react-server-dom-turbopacknpm | >= 19.2.0, < 19.2.8 | 19.2.8 |
react-server-dom-parcelnpm | >= 19.2.0, < 19.2.8 | 19.2.8 |
react-server-dom-webpacknpm | >= 19.2.0, < 19.2.8 | 19.2.8 |
Affected products
2- Range: 19.0.0-19.0.7, 19.1.0-19.1.8, 19.2.0-19.2.7
- Range: 19.0.0-19.0.7, 19.1.0-19.1.8, 19.2.0-19.2.7
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-wx67-qw84-cm4gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-44907ghsaADVISORY
- github.com/react/react/security/advisories/GHSA-wx67-qw84-cm4gghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.