Resource exhaustion in React - CVE-2026-44907
Published: July 22, 2026
React
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in server function endpoints when handling specially crafted HTTP requests. A remote attacker can send specially crafted HTTP requests to cause a denial of service.
Only applications using a server and a framework, bundler, or bundler plugin that supports React Server Components are affected.