CVE-2026-44907High· 7.5▾ Twilightreact-server-dom: Denial of Service in Server Functions
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 24.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.3%
0.3% → 0.6%
A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to out-of-memory exceptions or excessive CPU usage.
We recommend updating immediately.
The vulnerability exists in versions 19.0.0 through 19.0.7, 19.1.0 through 19.1.8, and 19.2.0 through 19.2.7 of:
Fixes were back ported to versions 19.0.8, 19.1.9, and 19.2.8.
If you are using any of the above packages please upgrade to any of the fixed versions immediately.
If your app’s React code does not use a server, your app is not affected by this vulnerability. If your app does not use a framework, bundler, or bundler plugin that supports React Server Components, your app is not affected by this vulnerability.
react-server-dom-webpack >= 19.0.0, < 19.0.8react-server-dom-turbopack >= 19.0.0, < 19.0.8react-server-dom-turbopack >= 19.1.0, < 19.1.9react-server-dom-parcel >= 19.1.0, < 19.1.9react-server-dom-webpack >= 19.1.0, < 19.1.9react-server-dom-turbopack >= 19.2.0, < 19.2.8react-server-dom-parcel >= 19.2.0, < 19.2.8react-server-dom-webpack >= 19.2.0, < 19.2.8Upgrade to a patched release:
react-server-dom-webpack 19.0.8react-server-dom-turbopack 19.0.8react-server-dom-turbopack 19.1.9react-server-dom-parcel 19.1.9react-server-dom-webpack 19.1.9react-server-dom-turbopack 19.2.8react-server-dom-parcel 19.2.8react-server-dom-webpack 19.2.8Connected by shared product, vendor, weakness, or advisory.
CVE-2024-12254High· 7.5Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines() method would not "pause" writing and signal to the Protocol to drain the buffer to the wire once the write buffer reached the "high-water mark"
CVE-2026-25535High· 7.5jsPDF is a library to generate PDFs in JavaScript
CVE-2026-14257High· 7.5brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257)
CVE-2026-12151High· 7.5undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)
CVE-2026-45768High· 7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine
CVE-2026-45765High· 7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine