VulnSea

facebook has 3 CVEs on record between 2025 and 2026. The median CVSS is 7.5 (high), with 1 rated critical. Most affected products: react (2), react-server-dom-parcel (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
33% vs 1% corpus
Median CVSS
7.5
Publish → KEV
(1)
Last 90 days
0 prev 1

Products

  • react 2
  • react-server-dom-parcel 1
3
Total CVEs
1
Critical
1
CISA KEV
1
Exploited

facebook vulnerabilities

CVEs affecting facebook, newest first. Open any entry for full detail, references, and exploit status.

3 CVEsRSS

CVE-2026-23870High· 7.5PoC
4mo ago

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following pac…

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following pac…

Midnightfacebook · react-server-dom-parcelEPSS 1.5%via NVD
CVE-2026-23864High· 7.5
7mo ago

Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending s…

Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending s…

Twilightfacebook · reactEPSS 2.5%via NVD
CVE-2025-55182Critical· 10.0CISA KEVPoC
9mo ago

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-serve…

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-serve…

Hadalfacebook · reactEPSS 100%via NVD
facebook vulnerabilities (CVEs) · VulnSea