CVE-2026-23869 is a denial of service (DoS) vulnerability affecting React Server Components, specifically the packages react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4). The vulnerability is triggered by sending specially crafted HTTP requests to Server Function endpoints, causing excessive C [truncated]
CVE-2025-55182 is a Meta React Server Components remote code execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-12-05. Because it is KEV-listed and marked as known to be used in ransomware campaigns, organizations should treat affected internet-facing React Server Components deployments as urgent priorities for mitigation, validation, and exposure review. CISA’s [truncated]