react-server-dom-parcel is vulnerable to Denial of Service
75
High Risk
A denial of service vulnerability exists in the React Server Components / React Flight server function handling shipped by this package. An attacker can send specially crafted HTTP requests to server function endpoints, causing the server to allocate resources without imposing limits or throttling. This can lead to out-of-memory exceptions or excessive CPU usage that degrade or crash the server process. The fix constrains how server function request payloads are decoded and handled.
You are affected if you are using a version that falls within the vulnerable range and your application uses React Server Components server function endpoints through a supported framework or bundler.
react-server-dom-parcel is vulnerable to Denial of Service in versions 19.0.0 - 19.0.7, 19.1.0 - 19.1.8 and 19.2.0 - 19.2.7.
Upgrade the react-server-dom-parcel library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant