CVE-2026-44907 | Meta react-server-dom-webpack up to 19.0.7/19.1.8/19.2.7 HTTP deserialization

SecurityVulns

A vulnerability classified as problematic was found in Meta react-server-dom-webpack, react-server-dom-parcel and react-server-dom-turbopack up to 19.0.7/19.1.8/19.2.7. Impacted is an unknown function of the component HTTP Handler. Executing a manipulation can lead to deserialization.

This vulnerability appears as CVE-2026-44907. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More