{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/react-server-dom-turbopack-versions-19.0.0-19.0.7-19.1.0-19.1.8-19.2.0-19.2.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-44907"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["react-server-dom-webpack (versions 19.0.0-19.0.7, 19.1.0-19.1.8, 19.2.0-19.2.7)","react-server-dom-parcel (versions 19.0.0-19.0.7, 19.1.0-19.1.8, 19.2.0-19.2.7)","react-server-dom-turbopack (versions 19.0.0-19.0.7, 19.1.0-19.1.8, 19.2.0-19.2.7)"],"_cs_severities":["low"],"_cs_tags":["react","denial-of-service","web","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Meta"],"content_html":"\u003cp\u003eA high-severity denial of service (DoS) vulnerability, identified as CVE-2026-44907, has been discovered in several core React Server Component packages maintained by Meta. This vulnerability affects \u003ccode\u003ereact-server-dom-webpack\u003c/code\u003e, \u003ccode\u003ereact-server-dom-parcel\u003c/code\u003e, and \u003ccode\u003ereact-server-dom-turbopack\u003c/code\u003e across various 19.x versions. Attackers can exploit this by sending maliciously crafted HTTP requests to application server function endpoints. Successful exploitation leads to severe resource consumption, including out-of-memory conditions or excessive CPU usage, causing the affected server to become unresponsive and resulting in a denial of service for legitimate users. This impacts applications that utilize React Server Components and do not run solely client-side. Immediate updates to patched versions (19.0.8, 19.1.9, 19.2.8) are crucial for all affected deployments.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker identifies a web application running vulnerable versions of React Server Component packages.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a specially designed HTTP request targeting a server function endpoint within the vulnerable React application.\u003c/li\u003e\n\u003cli\u003eThis malicious request exploits a flaw in the \u003ccode\u003ereact-server-dom-*\u003c/code\u003e package's processing logic.\u003c/li\u003e\n\u003cli\u003eThe vulnerable server consumes excessive amounts of memory or CPU resources while attempting to handle the crafted request.\u003c/li\u003e\n\u003cli\u003eThe server experiences resource exhaustion, leading to out-of-memory errors or extremely high CPU utilization.\u003c/li\u003e\n\u003cli\u003eThe web application becomes unresponsive or crashes, resulting in a denial of service for all users.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThis denial of service vulnerability can lead to significant operational disruption for web applications utilizing affected React Server Components. If exploited, the server hosting the application will become unresponsive, potentially leading to downtime, loss of business continuity, and reputational damage. The impact specifically includes out-of-memory exceptions and excessive CPU usage, which effectively incapacitate the server's ability to serve legitimate user requests. While the source does not provide specific victim counts or targeted sectors, any organization deploying applications with the vulnerable \u003ccode\u003ereact-server-dom-*\u003c/code\u003e packages is at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ePatch CVE-2026-44907 immediately\u003c/strong\u003e by upgrading the \u003ccode\u003ereact-server-dom-webpack\u003c/code\u003e, \u003ccode\u003ereact-server-dom-parcel\u003c/code\u003e, and \u003ccode\u003ereact-server-dom-turbopack\u003c/code\u003e packages to the fixed versions (19.0.8, 19.1.9, or 19.2.8, depending on your current major version).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eMonitor web server logs\u003c/strong\u003e for unusual or malformed HTTP requests targeting server function endpoints after applying patches, to confirm proper mitigation and detect any residual exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-24T21:16:16Z","date_published":"2026-07-24T21:16:16Z","id":"https://feed.craftedsignal.io/briefs/2026-07-react-server-dom-dos/","summary":"A denial of service vulnerability (CVE-2026-44907) affects multiple versions of the react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack packages, allowing threat actors to trigger out-of-memory exceptions or excessive CPU usage by sending specially crafted HTTP requests to server function endpoints.","title":"Denial of Service Vulnerability in React Server Components","url":"https://feed.craftedsignal.io/briefs/2026-07-react-server-dom-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - React-Server-Dom-Turbopack (Versions 19.0.0-19.0.7, 19.1.0-19.1.8, 19.2.0-19.2.7)","version":"https://jsonfeed.org/version/1.1"}