react-server-dom-parcel
npm8 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting react-server-dom-parcelpage 1 of 1
- CVE-2025-55182CRITICALCVSS 10.0EG 10.0⚠ KEVfixed in 19.0.1, 19.1.2 or 19.2.1, by version range2025-12-03
vulnerable: 19.2.0
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-…
- CVE-2025-55183HIGHCVSS 5.3EG 7.6fixed in 19.0.2, 19.1.3 or 19.2.2, by version range2025-12-11
An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-t…
- CVE-2025-55184HIGHCVSS 7.5EG 8.5fixed in 19.0.2, 19.1.3 or 19.2.2, by version range2025-12-11
A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack…
- CVE-2025-67779HIGHCVSS 7.5EG 7.5fixed in 19.0.3, 19.1.4 or 19.2.3, by version range2025-12-12
It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allo…
- CVE-2026-23864HIGHCVSS 7.5EG 7.5fixed in 19.0.4, 19.1.5 or 19.2.4, by version range2026-01-26
Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending spe…
- CVE-2026-23869HIGHCVSS 7.5EG 7.5fixed in 19.0.5, 19.1.6 or 19.2.5, by version range2026-04-08
A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.5,…
- CVE-2026-23870HIGHCVSS 7.5EG 7.5fixed in 19.0.6, 19.1.7 or 19.2.6, by version range2026-05-06
A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packa…
- CVE-2026-44907HIGHCVSS 7.5EG 7.5fixed in 19.1.9 or 19.2.8, by version range2026-07-21
A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-…
Check whether react-server-dom-parcel is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for react-server-dom-parcel CVEs against the assets you own.
Book a Demo →