Executive brief
@vitejs/plugin-rsc is a Vite plugin used to integrate React Server Components into React projects. The plugin vendors a vulnerable version of react-server-dom-webpack, which can be exploited by remote attackers to trigger a denial of service, causing the application to become unavailable without requiring authentication or user interaction.
Technical details
The vulnerability exists in vendored react-server-dom-webpack versions prior to 19.2.4, which is contained within @vitejs/plugin-rsc versions up to 0.5.22. The issue is classified as a denial of service (CWE-400) accessible over the network with no authentication required, no user interaction needed, and low attack complexity. An unauthenticated remote attacker can exploit this to cause high availability impact, making the affected application unavailable. The vulnerability has been patched in @vitejs/plugin-rsc version 0.5.23 and later.
Affected products
- Vitejs plugin-rsc <=0.5.22
Timeline
- 2026-04-10: disclosed
- 2026-04-10: patched: Fixed in version 0.5.23