{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-17T14:06:14.378","vulnerabilities":[{"cve":{"id":"CVE-2026-23864","sourceIdentifier":"cve-assign@fb.com","published":"2026-01-26T20:16:16.773","lastModified":"2026-02-13T15:23:05.013","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack.\n\nThe vulnerabilities are triggered by sending specially crafted HTTP requests to Server Function endpoints, and could lead to server crashes, out-of-memory exceptions or excessive CPU usage; depending on the vulnerable code path being exercised, the application configuration and application code.\n\nStrongly consider upgrading to the latest package versions to reduce risk and prevent availability issues in applications using React Server Components."},{"lang":"es","value":"Múltiples vulnerabilidades de denegación de servicio existen en los Componentes de Servidor de React, afectando los siguientes paquetes: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack.\n\nLas vulnerabilidades se activan al enviar solicitudes HTTP especialmente diseñadas a los puntos finales de las Funciones de Servidor, y podrían provocar caídas del servidor, excepciones por falta de memoria o uso excesivo de CPU; dependiendo de la ruta de código vulnerable que se esté ejecutando, la configuración de la aplicación y el código de la aplicación.\n\nConsidere encarecidamente actualizar a las últimas versiones de los paquetes para reducir el riesgo y prevenir problemas de disponibilidad en aplicaciones que utilizan Componentes de Servidor de React."}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-400"},{"lang":"en","value":"CWE-502"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:facebook:react:*:*:*:*:*:*:*:*","versionStartIncluding":"19.0.0","versionEndExcluding":"19.0.4","matchCriteriaId":"0F93D6DB-994E-428D-970C-D50737B628CF"},{"vulnerable":true,"criteria":"cpe:2.3:a:facebook:react:*:*:*:*:*:*:*:*","versionStartIncluding":"19.1.0","versionEndExcluding":"19.1.5","matchCriteriaId":"2151CF1A-4E87-421E-9714-3AA87639FD6B"},{"vulnerable":true,"criteria":"cpe:2.3:a:facebook:react:*:*:*:*:*:*:*:*","versionStartIncluding":"19.2.0","versionEndExcluding":"19.2.4","matchCriteriaId":"9FC73AD9-7EA4-4789-B75B-DC1FFF6F66AF"}]}]}],"references":[{"url":"https://www.facebook.com/security/advisories/cve-2026-23864","source":"cve-assign@fb.com","tags":["Vendor Advisory"]}]}}]}