Impact
The flaw exists in Meta’s React Server DOM packages for webpack, parcel, and turbopack. An attacker can send specially crafted HTTP requests to the server function endpoints, causing the server to consume excessive CPU resources. This leads to a denial of service by reducing system availability. The weakness is a classic uncontrolled resource consumption vulnerability (CWE‑400).
Affected Systems
Affected vendors are Meta, with the React Server DOM packages for webpack, parcel, and turbopack. The vulnerability impacts package versions 19.0.0 through 19.0.7, 19.1.0 through 19.1.8, and 19.2.0 through 19.2.7. All these versions expose the vulnerability until a patched release is applied.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. However, the EPSS score is less than 1 percent, suggesting a low probability of exploitation under current threat environments. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely remote over HTTP, requiring only the ability to send crafted requests to the affected endpoints. Because the exploit only demands network access, it is easy to launch from the internet, but the low exploitation probability mitigates immediate risk.
OpenCVE Enrichment
Github GHSA