VYPR
High severityNVD Advisory· Published Jul 21, 2026· Updated Jul 21, 2026

CVE-2026-44907

CVE-2026-44907

Description

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.7, 19.1.0 through 19.1.8, and 19.2.0 through 19.2.7).

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
react-server-dom-webpacknpm
>= 19.0.0, < 19.0.819.0.8
react-server-dom-turbopacknpm
>= 19.0.0, < 19.0.819.0.8
react-server-dom-turbopacknpm
>= 19.1.0, < 19.1.919.1.9
react-server-dom-parcelnpm
>= 19.1.0, < 19.1.919.1.9
react-server-dom-webpacknpm
>= 19.1.0, < 19.1.919.1.9
react-server-dom-turbopacknpm
>= 19.2.0, < 19.2.819.2.8
react-server-dom-parcelnpm
>= 19.2.0, < 19.2.819.2.8
react-server-dom-webpacknpm
>= 19.2.0, < 19.2.819.2.8

Affected products

2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.