Record summary

CVE-2026-44907 has a selected CVSS score of 7.5 (high).

Description

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.7, 19.1.0 through 19.1.8, and 19.2.0 through 19.2.7).

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 21, 2026 · Source: CVE List

Affected products and versions

6
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List19.0.0 to ≤ 19.0.7affected
19.1.0 to ≤ 19.1.8affected
19.2.0 to ≤ 19.2.7affected

Default status: unaffected

CVE List19.0.0 to ≤ 19.0.7affected
19.1.0 to ≤ 19.1.8affected
19.2.0 to ≤ 19.2.7affected

Default status: unaffected

CVE List19.0.0 to ≤ 19.0.7affected
19.1.0 to ≤ 19.1.8affected
19.2.0 to ≤ 19.2.7affected
GitHub Advisory19.1.0 to < 19.1.9 · Fixed in 19.1.9affected
19.2.0 to < 19.2.8 · Fixed in 19.2.8affected

react-server-dom-turbopack

Browse npm / react-server-dom-turbopack
GitHub Advisory19.0.0 to < 19.0.8 · Fixed in 19.0.8affected
19.1.0 to < 19.1.9 · Fixed in 19.1.9affected
19.2.0 to < 19.2.8 · Fixed in 19.2.8affected
GitHub Advisory19.0.0 to < 19.0.8 · Fixed in 19.0.8affected
19.1.0 to < 19.1.9 · Fixed in 19.1.9affected
19.2.0 to < 19.2.8 · Fixed in 19.2.8affected

References

3