Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rv78-f8rc-xrxh | Facebook React has a Denial of Service Vulnerability in React Server Components |
Thu, 07 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Facebook
Facebook react-server-dom-parcel Facebook react-server-dom-turbopack Facebook react-server-dom-webpack |
|
| Vendors & Products |
Facebook
Facebook react-server-dom-parcel Facebook react-server-dom-turbopack Facebook react-server-dom-webpack |
Wed, 06 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 06 May 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Denial of Service via Crafted HTTP Requests in Meta React Server DOM Packages | |
| Weaknesses | CWE-770 |
Wed, 06 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.5, 19.1.0 through 19.1.6, and 19.2.0 through 19.2.5). | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Meta
Published:
Updated: 2026-05-06T19:06:00.435Z
Reserved: 2026-01-16T19:49:26.309Z
Link: CVE-2026-23870
Updated: 2026-05-06T19:05:53.869Z
Status : Awaiting Analysis
Published: 2026-05-06T17:16:22.043
Modified: 2026-05-07T14:52:27.380
Link: CVE-2026-23870
No data.
OpenCVE Enrichment
Updated: 2026-05-07T18:15:34Z
Github GHSA