MetaCVE-2026-44907
Meta react-server-dom-parcel: denial of service
High7.5CVE-2026-44907 · Published Jul 21, 2026
A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.7, 19.1.0 through 19.1.8, and 19.2.0 through 19.2.7).
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| react-server-dom-parcel Product | >= 19.0.0, <= 19.0.7 | No fix yet |
| >= 19.1.0, <= 19.1.8 | No fix yet | |
| >= 19.2.0, <= 19.2.7 | No fix yet | |
| react-server-dom-turbopack Product | >= 19.0.0, <= 19.0.7 | No fix yet |
| >= 19.1.0, <= 19.1.8 | No fix yet | |
| >= 19.2.0, <= 19.2.7 | No fix yet | |
| react-server-dom-webpack Product | >= 19.0.0, <= 19.0.7 | No fix yet |
| >= 19.1.0, <= 19.1.8 | No fix yet | |
| >= 19.2.0, <= 19.2.7 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- the vendor (its own CVE record or advisory)
More Meta advisories
All Meta| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 23 | Meta proxygen: resource exhaustion | High7.5 | v2026.07.20.00 |