Vendor
high
advisory
Vite Dev Server `server.fs.deny` Bypass on Windows (CVE-2026-53571)
2 rules 1 TTP 1 CVE 3 IOCsA high-severity vulnerability (CVE-2026-53571) in the Vite development server on Windows allows threat actors to bypass `server.fs.deny` restrictions, leading to information disclosure of sensitive files like `.env` or `tls.pem` via crafted HTTP requests utilizing NTFS Alternate Data Streams or 8.3 short names, impacting applications that expose the dev server to the network.
PoC
Vite +4
information-disclosure
bypass
web-vulnerability
windows
development-server
2r
1t
1c
3i
updated
medium
advisory
@vitejs/plugin-rsc Denial-of-Service Vulnerability in React Server Components
2 rules 1 TTP 1 CVE@vitejs/plugin-rsc is vulnerable to a denial-of-service attack due to an embedded vulnerable version of react-server-dom-webpack, potentially causing resource exhaustion.
@vitejs/plugin-rsc +1
denial-of-service
react
vite
2r
1t
1c