Description
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
Remediation
References
Related Vulnerabilities
Jetty CVE-2023-26049 Vulnerability (CVE-2023-26049)
WebLogic Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2018-1000180)
OpenSSL Other Vulnerability (CVE-2015-0289)
WordPress 4.1.x Possible SQL Injection Vulnerability (4.1 - 4.1.19)
WordPress Plugin WordPress Alipay/Tenpay/PayPal SQL Injection (3.7.2)