Bug 2467287 (CVE-2026-23870) - CVE-2026-23870 react-server-dom-webpack: react-server-dom-parcel: react-server-dom-turbopack: React Server DOM: Denial of Service via specially crafted HTTP requests
Summary: CVE-2026-23870 react-server-dom-webpack: react-server-dom-parcel: react-serve...
Keywords:
Status: NEW
Alias: CVE-2026-23870
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-06 17:01 UTC by OSIDB Bzimport
Modified: 2026-05-29 12:16 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-05-06 17:01:42 UTC
A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.5, 19.1.0 through 19.1.6, and 19.2.0 through 19.2.5).


Note You need to log in before you can comment on or make changes to this bug.