Executive brief
React Server Components is a feature in the React JavaScript library that allows server-side rendering and computation. A denial of service vulnerability allows unauthenticated attackers to send specially crafted HTTP requests to applications using these components, causing the server to consume excessive CPU for up to a minute, potentially making the application unresponsive to legitimate users. This affects three related npm packages used by popular frameworks like Next.js and React Router.
Technical details
This vulnerability resides in the deserialization logic of React Server Components (CWE-502: Deserialization of Untrusted Data, CWE-400: Uncontrolled Resource Consumption). When a specially crafted HTTP request is sent to a Server Function endpoint, the deserialization process triggers an infinite loop or excessive resource allocation, causing the server process to hang and consume CPU for up to a minute before throwing a catchable error. The attack requires network access to the Server Function endpoint and no authentication or user interaction. An attacker can cause denial of service to all application users. Patches have been backported to versions 19.0.5, 19.1.6, and 19.2.5 of react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack.
Affected products
- Meta react-server-dom-webpack 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, 19.2.0 through 19.2.4
- Meta react-server-dom-parcel 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, 19.2.0 through 19.2.4
- Meta react-server-dom-turbopack 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, 19.2.0 through 19.2.4
Timeline
- 2026-04-10: disclosed: Vulnerability disclosed as GHSA-479c-33wc-g2pg
- 2026-04-10: patched: Patches released in versions 19.0.5, 19.1.6, and 19.2.5