Search

Find a vulnerability

Search criteria

    376 vulnerabilities by Facebook

    CVE-2026-91096 (GCVE-0-2026-91096)

    Vulnerability from nvd – Published: 2026-09-28 20:44 – Updated: 2026-09-30 19:47
    VLAI
    Summary
    In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::terminateSessionStreams (WebTransportImpl::destroy in releases before v2025.08.18.00) failed to unregister read callbacks for streams that were no longer open before destroying them. The transport could then invoke a read callback that had been freed.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 19:47 UTC
    CWE
    • Use After Free (CWE-416)
    • CWE-416 - Use After Free
    References
    Impacted products
    Vendor Product Version
    Facebook proxygen Affected: v2024.10.28.00 , < v2026.09.28.00 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-91096",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T19:47:52.478208Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-416",
                    "description": "CWE-416 Use After Free",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T19:47:55.479Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "proxygen",
              "vendor": "Facebook",
              "versions": [
                {
                  "lessThan": "v2026.09.28.00",
                  "status": "affected",
                  "version": "v2024.10.28.00",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "dateAssigned": "2026-09-14T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::terminateSessionStreams (WebTransportImpl::destroy in releases before v2025.08.18.00) failed to unregister read callbacks for streams that were no longer open before destroying them. The transport could then invoke a read callback that had been freed."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Use After Free (CWE-416)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T20:44:57.363Z",
            "orgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
            "shortName": "Meta"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.facebook.com/security/advisories/cve-2026-91096"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/facebook/proxygen/commit/479eb5574195764e80e6cedebef669f6baa85083"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
        "assignerShortName": "Meta",
        "cveId": "CVE-2026-91096",
        "datePublished": "2026-09-28T20:44:57.363Z",
        "dateReserved": "2026-09-14T18:40:39.036Z",
        "dateUpdated": "2026-09-30T19:47:55.479Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-91095 (GCVE-0-2026-91095)

    Vulnerability from nvd – Published: 2026-09-28 20:44 – Updated: 2026-09-30 19:49
    VLAI
    Summary
    In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStream APIs could return stream handles that the stream handler had already freed. HQSession then installed those handles as transport read callbacks, which could lead to use of freed memory.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 19:49 UTC
    CWE
    • Use After Free (CWE-416)
    • CWE-416 - Use After Free
    References
    Impacted products
    Vendor Product Version
    Facebook proxygen Affected: v2024.10.28.00 , < v2026.09.28.00 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "LOW",
                  "baseScore": 5.3,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-91095",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T19:49:10.823542Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-416",
                    "description": "CWE-416 Use After Free",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T19:49:15.429Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "proxygen",
              "vendor": "Facebook",
              "versions": [
                {
                  "lessThan": "v2026.09.28.00",
                  "status": "affected",
                  "version": "v2024.10.28.00",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "dateAssigned": "2026-09-14T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStream APIs could return stream handles that the stream handler had already freed. HQSession then installed those handles as transport read callbacks, which could lead to use of freed memory."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Use After Free (CWE-416)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T20:44:45.928Z",
            "orgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
            "shortName": "Meta"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.facebook.com/security/advisories/cve-2026-91095"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/facebook/proxygen/commit/479eb5574195764e80e6cedebef669f6baa85083"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
        "assignerShortName": "Meta",
        "cveId": "CVE-2026-91095",
        "datePublished": "2026-09-28T20:44:45.928Z",
        "dateReserved": "2026-09-14T18:40:39.036Z",
        "dateUpdated": "2026-09-30T19:49:15.429Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84895 (GCVE-0-2026-84895)

    Vulnerability from nvd – Published: 2026-09-28 20:44 – Updated: 2026-10-01 14:02
    VLAI
    Summary
    In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSessionBase::closeSession method. The base method notifies the session handler, which may release the last reference to the session and destroy it.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 14:01 UTC
    CWE
    • Use After Free (CWE-416)
    • CWE-416 - Use After Free
    References
    Impacted products
    Vendor Product Version
    Facebook proxygen Affected: v2026.04.06.00 , < v2026.09.28.00 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "LOW",
                  "baseScore": 7.3,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "LOW",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84895",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T14:01:47.375791Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-416",
                    "description": "CWE-416 Use After Free",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T14:02:23.724Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "proxygen",
              "vendor": "Facebook",
              "versions": [
                {
                  "lessThan": "v2026.09.28.00",
                  "status": "affected",
                  "version": "v2026.04.06.00",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "dateAssigned": "2026-09-02T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSessionBase::closeSession method. The base method notifies the session handler, which may release the last reference to the session and destroy it."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Use After Free (CWE-416)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T20:44:34.886Z",
            "orgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
            "shortName": "Meta"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.facebook.com/security/advisories/cve-2026-84895"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/facebook/proxygen/commit/479eb5574195764e80e6cedebef669f6baa85083"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
        "assignerShortName": "Meta",
        "cveId": "CVE-2026-84895",
        "datePublished": "2026-09-28T20:44:34.886Z",
        "dateReserved": "2026-09-02T14:52:36.354Z",
        "dateUpdated": "2026-10-01T14:02:23.724Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-66707 (GCVE-0-2026-66707)

    Vulnerability from nvd – Published: 2026-08-06 14:28 – Updated: 2026-08-08 02:01
    VLAI
    Title
    WordPress Facebook for WooCommerce plugin <= 3.7.5 - Cross Site Scripting (XSS) vulnerability
    Summary
    Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-08 02:01 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    References
    Impacted products
    Vendor Product Version
    Facebook Facebook for WooCommerce Affected: n/a , ≤ 3.7.5 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-66707",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-08T02:01:06.216090Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-08T02:01:19.860Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "packageName": "facebook-for-woocommerce",
              "product": "Facebook for WooCommerce",
              "vendor": "Facebook",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "3.7.6",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "3.7.5",
                  "status": "affected",
                  "version": "n/a",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Rafie Muhammad | Patchstack Bug Bounty Program"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce \u003c= 3.7.5 versions."
                }
              ],
              "value": "Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce \u003c= 3.7.5 versions."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-591",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-591 Reflected XSS"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-06T14:28:08.911Z",
            "orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
            "shortName": "Patchstack"
          },
          "references": [
            {
              "tags": [
                "vdb-entry"
              ],
              "url": "https://patchstack.com/database/wordpress/plugin/facebook-for-woocommerce/vulnerability/wordpress-facebook-for-woocommerce-plugin-3-7-5-cross-site-scripting-xss-vulnerability?_s_id=cve"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Update the WordPress Facebook for WooCommerce Plugin to the latest available version (at least 3.7.6)."
                }
              ],
              "value": "Update the WordPress Facebook for WooCommerce Plugin to the latest available version (at least 3.7.6)."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "WordPress Facebook for WooCommerce plugin \u003c= 3.7.5 - Cross Site Scripting (XSS) vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
        "assignerShortName": "Patchstack",
        "cveId": "CVE-2026-66707",
        "datePublished": "2026-08-06T14:28:08.911Z",
        "dateReserved": "2026-07-27T14:01:16.156Z",
        "dateUpdated": "2026-08-08T02:01:19.860Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-66705 (GCVE-0-2026-66705)

    Vulnerability from nvd – Published: 2026-08-06 14:28 – Updated: 2026-08-06 15:04
    VLAI
    Title
    WordPress Facebook for WordPress plugin <= 5.2.1 - Cross Site Scripting (XSS) vulnerability
    Summary
    Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-06 15:03 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    References
    Impacted products
    Vendor Product Version
    Facebook Facebook for WordPress Affected: n/a , ≤ 5.2.1 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-66705",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-06T15:03:52.504021Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-06T15:04:00.807Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "packageName": "official-facebook-pixel",
              "product": "Facebook for WordPress",
              "vendor": "Facebook",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "5.2.2",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "5.2.1",
                  "status": "affected",
                  "version": "n/a",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Rafie Muhammad | Patchstack Bug Bounty Program"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress \u003c= 5.2.1 versions."
                }
              ],
              "value": "Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress \u003c= 5.2.1 versions."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-591",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-591 Reflected XSS"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-06T14:28:07.562Z",
            "orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
            "shortName": "Patchstack"
          },
          "references": [
            {
              "tags": [
                "vdb-entry"
              ],
              "url": "https://patchstack.com/database/wordpress/plugin/official-facebook-pixel/vulnerability/wordpress-facebook-for-wordpress-plugin-5-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Update the WordPress Facebook for WordPress Plugin to the latest available version (at least 5.2.2)."
                }
              ],
              "value": "Update the WordPress Facebook for WordPress Plugin to the latest available version (at least 5.2.2)."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "WordPress Facebook for WordPress plugin \u003c= 5.2.1 - Cross Site Scripting (XSS) vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
        "assignerShortName": "Patchstack",
        "cveId": "CVE-2026-66705",
        "datePublished": "2026-08-06T14:28:07.562Z",
        "dateReserved": "2026-07-27T14:01:16.156Z",
        "dateUpdated": "2026-08-06T15:04:00.807Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-44909 (GCVE-0-2026-44909)

    Vulnerability from nvd – Published: 2026-07-23 16:27 – Updated: 2026-07-23 19:07
    VLAI
    Summary
    Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW_SIZE to 0 or withholding WINDOW_UPDATE frames, causing the server to buffer complete response bodies in memory indefinitely for stalled streams. By opening many simultaneous streams requesting large resources while preventing the server from transmitting responses, an attacker could induce unbounded memory growth leading to service degradation, resource exhaustion, or denial of service. Versions v2017.01.16.00 through v2026.07.20.00 are affected.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-23 19:07 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    Facebook proxygen Affected: v2017.01.16.00 , < v2026.07.20.00 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-44909",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-23T19:07:17.371673Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-23T19:07:28.874Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "proxygen",
              "vendor": "Facebook",
              "versions": [
                {
                  "lessThan": "v2026.07.20.00",
                  "status": "affected",
                  "version": "v2017.01.16.00",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "dateAssigned": "2026-07-15T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW_SIZE to 0 or withholding WINDOW_UPDATE frames, causing the server to buffer complete response bodies in memory indefinitely for stalled streams. By opening many simultaneous streams requesting large resources while preventing the server from transmitting responses, an attacker could induce unbounded memory growth leading to service degradation, resource exhaustion, or denial of service. Versions v2017.01.16.00 through v2026.07.20.00 are affected."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-770",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-23T16:27:01.658Z",
            "orgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
            "shortName": "Meta"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/facebook/proxygen/commit/f28742f21f7022c261b7620d4e6b20d82b6cff72"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
        "assignerShortName": "Meta",
        "cveId": "CVE-2026-44909",
        "datePublished": "2026-07-23T16:27:01.658Z",
        "dateReserved": "2026-05-08T02:33:35.450Z",
        "dateUpdated": "2026-07-23T19:07:28.874Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-49059 (GCVE-0-2026-49059)

    Vulnerability from nvd – Published: 2026-05-27 14:33 – Updated: 2026-05-28 00:33 X_Open Source
    VLAI
    Title
    WordPress Facebook for WooCommerce plugin <= 3.7.0 - Open Redirection vulnerability
    Summary
    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Facebook Facebook for WooCommerce allows Phishing. This issue affects Facebook for WooCommerce: from n/a through 3.7.0.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-05-28 00:33 UTC
    CWE
    • CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')
    References
    Impacted products
    Vendor Product Version
    Facebook Facebook for WooCommerce Affected: n/a , ≤ 3.7.0 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-49059",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-05-28T00:33:31.656838Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-28T00:33:43.335Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "packageName": "facebook-for-woocommerce",
              "product": "Facebook for WooCommerce",
              "vendor": "Facebook",
              "versions": [
                {
                  "lessThanOrEqual": "3.7.0",
                  "status": "affected",
                  "version": "n/a",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "timomangcut | Patchstack Bug Bounty Program"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "URL Redirection to Untrusted Site (\u0027Open Redirect\u0027) vulnerability in Facebook Facebook for WooCommerce allows Phishing.\u003cp\u003eThis issue affects Facebook for WooCommerce: from n/a through 3.7.0.\u003c/p\u003e"
                }
              ],
              "value": "URL Redirection to Untrusted Site (\u0027Open Redirect\u0027) vulnerability in Facebook Facebook for WooCommerce allows Phishing.\n\nThis issue affects Facebook for WooCommerce: from n/a through 3.7.0."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-98",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-98 Phishing"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.7,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-601",
                  "description": "CWE-601 URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-27T14:33:18.844Z",
            "orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
            "shortName": "Patchstack"
          },
          "references": [
            {
              "tags": [
                "vdb-entry"
              ],
              "url": "https://patchstack.com/database/wordpress/plugin/facebook-for-woocommerce/vulnerability/wordpress-facebook-for-woocommerce-plugin-3-7-0-open-redirection-vulnerability?_s_id=cve"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "tags": [
            "x_open-source"
          ],
          "title": "WordPress Facebook for WooCommerce plugin \u003c= 3.7.0 - Open Redirection vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
        "assignerShortName": "Patchstack",
        "cveId": "CVE-2026-49059",
        "datePublished": "2026-05-27T14:33:18.844Z",
        "dateReserved": "2026-05-27T10:26:36.700Z",
        "dateUpdated": "2026-05-28T00:33:43.335Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-23870 (GCVE-0-2026-23870)

    Vulnerability from nvd – Published: 2026-05-06 16:24 – Updated: 2026-05-06 19:06
    VLAI
    Summary
    A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.5, 19.1.0 through 19.1.6, and 19.2.0 through 19.2.5).
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-05-06 19:03 UTC
    CWE
    • (CWE-502) Deserialization of Untrusted Data, (CWE-400) Uncontrolled Resource Consumption
    References
    Impacted products
    Vendor Product Version
    Meta react-server-dom-turbopack Affected: 19.0.0 , ≤ 19.0.5 (semver)
    Affected: 19.1.0 , ≤ 19.1.6 (semver)
    Affected: 19.2.0 , ≤ 19.2.5 (semver)
    Create a notification for this product.
    Meta react-server-dom-parcel Affected: 19.0.0 , ≤ 19.0.5 (semver)
    Affected: 19.1.0 , ≤ 19.1.6 (semver)
    Affected: 19.2.0 , ≤ 19.2.5 (semver)
    Create a notification for this product.
    Meta react-server-dom-webpack Affected: 19.0.0 , ≤ 19.0.5 (semver)
    Affected: 19.1.0 , ≤ 19.1.6 (semver)
    Affected: 19.2.0 , ≤ 19.2.5 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-23870",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-05-06T19:03:16.700440Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-06T19:06:00.435Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-turbopack",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.5",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.6",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.5",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-parcel",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.5",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.6",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.5",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-webpack",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.5",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.6",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.5",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "dateAssigned": "2026-05-06T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.5, 19.1.0 through 19.1.6, and 19.2.0 through 19.2.5)."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "(CWE-502) Deserialization of Untrusted Data, (CWE-400) Uncontrolled Resource Consumption",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-06T16:24:55.620Z",
            "orgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
            "shortName": "Meta"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/facebook/react/security/advisories/GHSA-rv78-f8rc-xrxh"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
        "assignerShortName": "Meta",
        "cveId": "CVE-2026-23870",
        "datePublished": "2026-05-06T16:24:55.620Z",
        "dateReserved": "2026-01-16T19:49:26.309Z",
        "dateUpdated": "2026-05-06T19:06:00.435Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-23866 (GCVE-0-2026-23866)

    Vulnerability from nvd – Published: 2026-05-01 16:02 – Updated: 2026-05-01 17:42
    VLAI
    Summary
    Incomplete validation of AI rich response messages for Instagram Reels in WhatsApp for iOS v2.25.8.0 to v2.26.15.72 and WhatsApp for Android v2.25.8.0 to v2.26.7.10 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device, including triggering OS-controlled custom URL scheme handlers. We have not seen evidence of exploitation in the wild.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-05-01 17:41 UTC
    CWE
    • Improper Verification of Source of a Communication Channel (CWE-940)
    • CWE-940 - Improper Verification of Source of a Communication Channel
    References
    Impacted products
    Vendor Product Version
    Facebook WhatsApp for Android Affected: 2.25.8.0 , < 2.26.7.10 (semver)
    Create a notification for this product.
    Facebook WhatsApp for iOS Affected: 2.25.8.0 , < 2.26.15.72 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-23866",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-05-01T17:41:43.060585Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-940",
                    "description": "CWE-940 Improper Verification of Source of a Communication Channel",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-01T17:42:09.286Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WhatsApp for Android",
              "vendor": "Facebook",
              "versions": [
                {
                  "lessThan": "2.26.7.10",
                  "status": "affected",
                  "version": "2.25.8.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WhatsApp for iOS",
              "vendor": "Facebook",
              "versions": [
                {
                  "lessThan": "2.26.15.72",
                  "status": "affected",
                  "version": "2.25.8.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "dateAssigned": "2026-04-20T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Incomplete validation of AI rich response messages for Instagram Reels in WhatsApp for iOS v2.25.8.0 to v2.26.15.72 and WhatsApp for Android v2.25.8.0 to v2.26.7.10 could have allowed a user to trigger processing of media content from an arbitrary URL on another user\u2019s device, including triggering OS-controlled custom URL scheme handlers. We have not seen evidence of exploitation in the wild."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:F/RL:O/RC:C",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Improper Verification of Source of a Communication Channel (CWE-940)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-01T16:10:25.306Z",
            "orgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
            "shortName": "Meta"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.facebook.com/security/advisories/cve-2026-23866"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.whatsapp.com/security/advisories/2026"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
        "assignerShortName": "Meta",
        "cveId": "CVE-2026-23866",
        "datePublished": "2026-05-01T16:02:03.304Z",
        "dateReserved": "2026-01-16T19:49:26.309Z",
        "dateUpdated": "2026-05-01T17:42:09.286Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-23863 (GCVE-0-2026-23863)

    Vulnerability from nvd – Published: 2026-05-01 16:01 – Updated: 2026-05-01 17:41
    VLAI
    Summary
    An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously formatted documents with embedded NUL bytes in the filename to be shown in the application as one type of file but run as an executable when opened. We have not seen evidence of exploitation in the wild.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-05-01 17:40 UTC
    CWE
    • Improper Neutralization of Null Byte or NUL Character (CWE-158)
    • CWE-158 - Improper Neutralization of Null Byte or NUL Character
    References
    Impacted products
    Vendor Product Version
    Facebook WhatsApp Desktop for Windows Affected: 2.3000.*.252500 , < 2.3000.1032164386.258709 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-23863",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-05-01T17:40:45.569668Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-158",
                    "description": "CWE-158 Improper Neutralization of Null Byte or NUL Character",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-01T17:41:14.681Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WhatsApp Desktop for Windows",
              "vendor": "Facebook",
              "versions": [
                {
                  "lessThan": "2.3000.1032164386.258709",
                  "status": "affected",
                  "version": "2.3000.*.252500",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "dateAssigned": "2026-04-20T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously formatted documents with embedded NUL bytes in the filename to be shown in the application as one type of file but run as an executable when opened. We have not seen evidence of exploitation in the wild."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:F/RL:O/RC:C",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Improper Neutralization of Null Byte or NUL Character (CWE-158)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-01T16:15:38.171Z",
            "orgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
            "shortName": "Meta"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.facebook.com/security/advisories/cve-2026-23863"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.whatsapp.com/security/advisories/2026"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
        "assignerShortName": "Meta",
        "cveId": "CVE-2026-23863",
        "datePublished": "2026-05-01T16:01:39.565Z",
        "dateReserved": "2026-01-16T19:49:26.308Z",
        "dateUpdated": "2026-05-01T17:41:14.681Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-23864 (GCVE-0-2026-23864)

    Vulnerability from nvd – Published: 2026-01-26 19:16 – Updated: 2026-07-15 01:18
    VLAI
    Summary
    Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending specially crafted HTTP requests to Server Function endpoints, and could lead to server crashes, out-of-memory exceptions or excessive CPU usage; depending on the vulnerable code path being exercised, the application configuration and application code. Strongly consider upgrading to the latest package versions to reduce risk and prevent availability issues in applications using React Server Components.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-01-26 20:26 UTC
    CWE
    • (CWE-502): Deserialization of Untrusted Data. (CWE-400): Uncontrolled Resource Consumption
    • CWE-502 - Deserialization of Untrusted Data
    • CWE-400 - Uncontrolled Resource Consumption
    • CWE-1284 - Improper Validation of Specified Quantity in Input
    References
    Impacted products
    Vendor Product Version
    Meta react-server-dom-webpack Affected: 19.0.0 , < 19.0.4 (semver)
    Affected: 19.1.0 , < 19.1.5 (semver)
    Affected: 19.2.0 , < 19.2.4 (semver)
    Create a notification for this product.
    Meta react-server-dom-turbopack Affected: 19.0.0 , < 19.0.4 (semver)
    Affected: 19.1.0 , < 19.1.5 (semver)
    Affected: 19.2.0 , < 19.2.4 (semver)
    Create a notification for this product.
    Meta react-server-dom-parcel Affected: 19.0.0 , < 19.0.4 (semver)
    Affected: 19.1.0 , < 19.1.5 (semver)
    Affected: 19.2.0 , < 19.2.4 (semver)
    Create a notification for this product.
    Red Hat Streams for Apache Kafka 2.9.4     cpe:/a:redhat:amq_streams:2.9::el9
    Create a notification for this product.
    Red Hat Streams for Apache Kafka 3.2.0     cpe:/a:redhat:amq_streams:3.2::el9
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-23864",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-01-26T20:26:03.428817Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-502",
                    "description": "CWE-502 Deserialization of Untrusted Data",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              },
              {
                "descriptions": [
                  {
                    "cweId": "CWE-400",
                    "description": "CWE-400 Uncontrolled Resource Consumption",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-01-26T20:26:45.709Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "affected": [
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/a:redhat:amq_streams:2.9::el9"
                ],
                "defaultStatus": "unaffected",
                "packageName": "com.github.streamshub-console",
                "product": "Streams for Apache Kafka 2.9.4",
                "vendor": "Red Hat"
              },
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/a:redhat:amq_streams:3.2::el9"
                ],
                "defaultStatus": "unaffected",
                "packageName": "com.github.streamshub-console",
                "product": "Streams for Apache Kafka 3.2.0",
                "vendor": "Red Hat"
              }
            ],
            "datePublic": "2026-01-26T19:16:38.250Z",
            "descriptions": [
              {
                "lang": "en",
                "value": "A flaw was found in React Server Components. A remote attacker can exploit this vulnerability by sending specially crafted HTTP requests to Server Function endpoints. This can lead to a Denial of Service (DoS), causing server crashes, out-of-memory exceptions, or excessive CPU usage, thereby impacting the availability of applications."
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "namespace": "https://access.redhat.com/security/updates/classification/",
                    "value": "Important"
                  },
                  "type": "Red Hat severity rating"
                }
              },
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                },
                "format": "CVSS"
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-1284",
                    "description": "Improper Validation of Specified Quantity in Input",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-15T01:18:01.838Z",
              "orgId": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "shortName": "redhat-SADP"
            },
            "references": [
              {
                "tags": [
                  "vdb-entry",
                  "x_refsource_REDHAT"
                ],
                "url": "https://access.redhat.com/security/cve/CVE-2026-23864"
              },
              {
                "name": "RHBZ#2433059",
                "tags": [
                  "issue-tracking",
                  "x_refsource_REDHAT"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433059"
              },
              {
                "tags": [
                  "x_sadp-csaf-vex"
                ],
                "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23864.json"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2026:34608"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2026:13571"
              }
            ],
            "solutions": [
              {
                "lang": "en",
                "value": "RHSA-2026:34608: Streams for Apache Kafka 2.9.4"
              },
              {
                "lang": "en",
                "value": "RHSA-2026:13571: Streams for Apache Kafka 3.2.0"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2026-01-26T20:01:54.396Z",
                "value": "Reported to Red Hat."
              },
              {
                "lang": "en",
                "time": "2026-01-26T19:16:38.250Z",
                "value": "Made public."
              }
            ],
            "title": "react-server-dom-webpack: react-server-dom-parcel: reactreact-server-dom-turbopack: React Server Components: Denial of Service via specially crafted HTTP requests",
            "x_adpType": "supplier",
            "x_generator": {
              "engine": "sadp-cli 1.0.0"
            }
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-webpack",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThan": "19.0.4",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "19.1.5",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "19.2.4",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-turbopack",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThan": "19.0.4",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "19.1.5",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "19.2.4",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-parcel",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThan": "19.0.4",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "19.1.5",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "19.2.4",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack.\n\nThe vulnerabilities are triggered by sending specially crafted HTTP requests to Server Function endpoints, and could lead to server crashes, out-of-memory exceptions or excessive CPU usage; depending on the vulnerable code path being exercised, the application configuration and application code.\n\nStrongly consider upgrading to the latest package versions to reduce risk and prevent availability issues in applications using React Server Components."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "(CWE-502): Deserialization of Untrusted Data. (CWE-400): Uncontrolled Resource Consumption",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-01-26T19:16:38.250Z",
            "orgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
            "shortName": "Meta"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.facebook.com/security/advisories/cve-2026-23864"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
        "assignerShortName": "Meta",
        "cveId": "CVE-2026-23864",
        "datePublished": "2026-01-26T19:16:38.250Z",
        "dateReserved": "2026-01-16T19:49:26.309Z",
        "dateUpdated": "2026-07-15T01:18:01.838Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-67779 (GCVE-0-2025-67779)

    Vulnerability from nvd – Published: 2025-12-11 23:36 – Updated: 2025-12-12 18:40
    VLAI
    Summary
    It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe deserialization of payloads from HTTP requests to Server Function endpoints. This can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-12-12 18:39 UTC
    CWE
    • (CWE-502) Deserialization of Untrusted Data, (CWE-400) Uncontrolled Resource Consumption
    • CWE-502 - Deserialization of Untrusted Data
    • CWE-400 - Uncontrolled Resource Consumption
    References
    Impacted products
    Vendor Product Version
    Meta react-server-dom-parcel Affected: 19.0.2 , ≤ 19.0.2 (semver)
    Affected: 19.1.3 , ≤ 19.1.3 (semver)
    Affected: 19.2.2 , ≤ 19.2.2 (semver)
    Create a notification for this product.
    Meta react-server-dom-turbopack Affected: 19.0.2 , ≤ 19.0.2 (semver)
    Affected: 19.1.3 , ≤ 19.1.3 (semver)
    Affected: 19.2.2 , ≤ 19.2.2 (semver)
    Create a notification for this product.
    Meta react-server-dom-webpack Affected: 19.0.2 , ≤ 19.0.2 (semver)
    Affected: 19.1.3 , ≤ 19.1.3 (semver)
    Affected: 19.2.2 , ≤ 19.2.2 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-67779",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-12-12T18:39:24.796538Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-502",
                    "description": "CWE-502 Deserialization of Untrusted Data",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              },
              {
                "descriptions": [
                  {
                    "cweId": "CWE-400",
                    "description": "CWE-400 Uncontrolled Resource Consumption",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-12-12T18:40:45.863Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-parcel",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.2",
                  "status": "affected",
                  "version": "19.0.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.3",
                  "status": "affected",
                  "version": "19.1.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.2",
                  "status": "affected",
                  "version": "19.2.2",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-turbopack",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.2",
                  "status": "affected",
                  "version": "19.0.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.3",
                  "status": "affected",
                  "version": "19.1.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.2",
                  "status": "affected",
                  "version": "19.2.2",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-webpack",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.2",
                  "status": "affected",
                  "version": "19.0.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.3",
                  "status": "affected",
                  "version": "19.1.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.2",
                  "status": "affected",
                  "version": "19.2.2",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "dateAssigned": "2025-12-11T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe deserialization of payloads from HTTP requests to Server Function endpoints. This can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "(CWE-502) Deserialization of Untrusted Data, (CWE-400) Uncontrolled Resource Consumption",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-12-11T23:36:20.699Z",
            "orgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
            "shortName": "Meta"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.facebook.com/security/advisories/cve-2025-67779"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
        "assignerShortName": "Meta",
        "cveId": "CVE-2025-67779",
        "datePublished": "2025-12-11T23:36:20.699Z",
        "dateReserved": "2025-12-11T22:58:08.827Z",
        "dateUpdated": "2025-12-12T18:40:45.863Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-55184 (GCVE-0-2025-55184)

    Vulnerability from nvd – Published: 2025-12-11 20:05 – Updated: 2025-12-15 16:37
    VLAI
    Summary
    A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints, which can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-12-15 16:36 UTC
    CWE
    • (CWE-502) Deserialization of Untrusted Data. (CWE-400) Uncontrolled Resource Consumption
    Impacted products
    Vendor Product Version
    Meta react-server-dom-webpack Affected: 19.0.0 , ≤ 19.0.1 (semver)
    Affected: 19.1.0 , ≤ 19.1.2 (semver)
    Affected: 19.2.0 , ≤ 19.2.1 (semver)
    Create a notification for this product.
    Meta react-server-dom-turbopack Affected: 19.0.0 , ≤ 19.0.1 (semver)
    Affected: 19.1.0 , ≤ 19.1.2 (semver)
    Affected: 19.2.0 , ≤ 19.2.1 (semver)
    Create a notification for this product.
    Meta react-server-dom-parcel Affected: 19.0.0 , ≤ 19.0.1 (semver)
    Affected: 19.1.0 , ≤ 19.1.2 (semver)
    Affected: 19.2.0 , ≤ 19.2.1 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-55184",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-12-15T16:36:27.831763Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-12-15T16:37:06.708Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/KingHacker353/CVE-2025-55184"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-webpack",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.1",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.2",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.1",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-turbopack",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.1",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.2",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.1",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-parcel",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.1",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.2",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.1",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "dateAssigned": "2025-12-09T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints, which can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "(CWE-502) Deserialization of Untrusted Data. (CWE-400) Uncontrolled Resource Consumption",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-12-11T20:11:26.262Z",
            "orgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
            "shortName": "Meta"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.facebook.com/security/advisories/cve-2025-55184"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
        "assignerShortName": "Meta",
        "cveId": "CVE-2025-55184",
        "datePublished": "2025-12-11T20:05:01.328Z",
        "dateReserved": "2025-08-08T18:21:47.119Z",
        "dateUpdated": "2025-12-15T16:37:06.708Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-55183 (GCVE-0-2025-55183)

    Vulnerability from nvd – Published: 2025-12-11 20:04 – Updated: 2026-01-07 16:26
    VLAI
    Summary
    An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. A specifically crafted HTTP request sent to a vulnerable Server Function may unsafely return the source code of any Server Function. Exploitation requires the existence of a Server Function which explicitly or implicitly exposes a stringified argument.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-01-07 16:24 UTC
    CWE
    • (CWE-502) Deserialization of Untrusted Data. (CWE-497) Exposure of Sensitive System Information to an Unauthorized Actor
    References
    Impacted products
    Vendor Product Version
    Meta react-server-dom-webpack Affected: 19.0.0 , ≤ 19.0.1 (semver)
    Affected: 19.1.0 , ≤ 19.1.2 (semver)
    Affected: 19.2.0 , ≤ 19.2.1 (semver)
    Create a notification for this product.
    Meta react-server-dom-turbopack Affected: 19.0.0 , ≤ 19.0.1 (semver)
    Affected: 19.1.0 , ≤ 19.1.2 (semver)
    Affected: 19.2.0 , ≤ 19.2.1 (semver)
    Create a notification for this product.
    Meta react-server-dom-parcel Affected: 19.0.0 , ≤ 19.0.1 (semver)
    Affected: 19.1.0 , ≤ 19.1.2 (semver)
    Affected: 19.2.0 , ≤ 19.2.1 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-55183",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-01-07T16:24:47.971492Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-01-07T16:26:47.826Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-webpack",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.1",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.2",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.1",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-turbopack",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.1",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.2",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.1",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-parcel",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.1",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.2",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.1",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "dateAssigned": "2025-12-09T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. A specifically crafted HTTP request sent to a vulnerable Server Function may unsafely return the source code of any Server Function. Exploitation requires the existence of a Server Function which explicitly or implicitly exposes a stringified argument."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "(CWE-502) Deserialization of Untrusted Data. (CWE-497) Exposure of Sensitive System Information to an Unauthorized Actor",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-12-11T20:09:32.286Z",
            "orgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
            "shortName": "Meta"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.facebook.com/security/advisories/cve-2025-55183"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
        "assignerShortName": "Meta",
        "cveId": "CVE-2025-55183",
        "datePublished": "2025-12-11T20:04:48.655Z",
        "dateReserved": "2025-08-08T18:21:47.119Z",
        "dateUpdated": "2026-01-07T16:26:47.826Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-55182 (GCVE-0-2025-55182)

    Vulnerability from nvd – Published: 2025-12-03 15:40 – Updated: 2026-08-04 03:56
    VLAI CISA ENISA Previdian
    Summary
    A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-12-03 00:00 UTC
    CWE
    • Deserialization of Untrusted Data (CWE-502)
    Impacted products
    Vendor Product Version
    Meta react-server-dom-webpack Affected: 19.0.0 , ≤ 19.0.0 (semver)
    Affected: 19.1.0 , ≤ 19.1.1 (semver)
    Affected: 19.2.0 , ≤ 19.2.0 (semver)
    Create a notification for this product.
    Meta react-server-dom-turbopack Affected: 19.0.0 , ≤ 19.0.0 (semver)
    Affected: 19.1.0 , ≤ 19.1.1 (semver)
    Affected: 19.2.0 , ≤ 19.2.0 (semver)
    Create a notification for this product.
    Meta react-server-dom-parcel Affected: 19.0.0 , ≤ 19.0.0 (semver)
    Affected: 19.1.0 , ≤ 19.1.1 (semver)
    Affected: 19.2.0 , ≤ 19.2.0 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-55182",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-12-03T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2025-12-05",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-55182"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-04T03:56:01.281Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "media-coverage"
                ],
                "url": "https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/"
              },
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-55182"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2025-12-05T00:00:00.000Z",
                "value": "CVE-2025-55182 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-12-04T17:32:12.884Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://www.openwall.com/lists/oss-security/2025/12/03/4"
              },
              {
                "url": "https://news.ycombinator.com/item?id=46136026"
              }
            ],
            "title": "CVE Program Container",
            "x_generator": {
              "engine": "ADPogram 0.0.1"
            }
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-webpack",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.0",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.1",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.0",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-turbopack",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.0",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.1",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.0",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-parcel",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.0",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.1",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.0",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "dateAssigned": "2025-12-02T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 10,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Deserialization of Untrusted Data (CWE-502)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-12-11T20:15:37.699Z",
            "orgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
            "shortName": "Meta"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.facebook.com/security/advisories/cve-2025-55182"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
        "assignerShortName": "Meta",
        "cveId": "CVE-2025-55182",
        "datePublished": "2025-12-03T15:40:56.894Z",
        "dateReserved": "2025-08-08T18:21:47.119Z",
        "dateUpdated": "2026-08-04T03:56:01.281Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-91096 (GCVE-0-2026-91096)

    Vulnerability from cvelistv5 – Published: 2026-09-28 20:44 – Updated: 2026-09-30 19:47
    VLAI
    Summary
    In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::terminateSessionStreams (WebTransportImpl::destroy in releases before v2025.08.18.00) failed to unregister read callbacks for streams that were no longer open before destroying them. The transport could then invoke a read callback that had been freed.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 19:47 UTC
    CWE
    • Use After Free (CWE-416)
    • CWE-416 - Use After Free
    References
    Impacted products
    Vendor Product Version
    Facebook proxygen Affected: v2024.10.28.00 , < v2026.09.28.00 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-91096",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T19:47:52.478208Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-416",
                    "description": "CWE-416 Use After Free",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T19:47:55.479Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "proxygen",
              "vendor": "Facebook",
              "versions": [
                {
                  "lessThan": "v2026.09.28.00",
                  "status": "affected",
                  "version": "v2024.10.28.00",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "dateAssigned": "2026-09-14T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::terminateSessionStreams (WebTransportImpl::destroy in releases before v2025.08.18.00) failed to unregister read callbacks for streams that were no longer open before destroying them. The transport could then invoke a read callback that had been freed."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Use After Free (CWE-416)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T20:44:57.363Z",
            "orgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
            "shortName": "Meta"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.facebook.com/security/advisories/cve-2026-91096"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/facebook/proxygen/commit/479eb5574195764e80e6cedebef669f6baa85083"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
        "assignerShortName": "Meta",
        "cveId": "CVE-2026-91096",
        "datePublished": "2026-09-28T20:44:57.363Z",
        "dateReserved": "2026-09-14T18:40:39.036Z",
        "dateUpdated": "2026-09-30T19:47:55.479Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-91095 (GCVE-0-2026-91095)

    Vulnerability from cvelistv5 – Published: 2026-09-28 20:44 – Updated: 2026-09-30 19:49
    VLAI
    Summary
    In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStream APIs could return stream handles that the stream handler had already freed. HQSession then installed those handles as transport read callbacks, which could lead to use of freed memory.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-30 19:49 UTC
    CWE
    • Use After Free (CWE-416)
    • CWE-416 - Use After Free
    References
    Impacted products
    Vendor Product Version
    Facebook proxygen Affected: v2024.10.28.00 , < v2026.09.28.00 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "LOW",
                  "baseScore": 5.3,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-91095",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-30T19:49:10.823542Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-416",
                    "description": "CWE-416 Use After Free",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-30T19:49:15.429Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "proxygen",
              "vendor": "Facebook",
              "versions": [
                {
                  "lessThan": "v2026.09.28.00",
                  "status": "affected",
                  "version": "v2024.10.28.00",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "dateAssigned": "2026-09-14T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStream APIs could return stream handles that the stream handler had already freed. HQSession then installed those handles as transport read callbacks, which could lead to use of freed memory."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Use After Free (CWE-416)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T20:44:45.928Z",
            "orgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
            "shortName": "Meta"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.facebook.com/security/advisories/cve-2026-91095"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/facebook/proxygen/commit/479eb5574195764e80e6cedebef669f6baa85083"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
        "assignerShortName": "Meta",
        "cveId": "CVE-2026-91095",
        "datePublished": "2026-09-28T20:44:45.928Z",
        "dateReserved": "2026-09-14T18:40:39.036Z",
        "dateUpdated": "2026-09-30T19:49:15.429Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84895 (GCVE-0-2026-84895)

    Vulnerability from cvelistv5 – Published: 2026-09-28 20:44 – Updated: 2026-10-01 14:02
    VLAI
    Summary
    In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSessionBase::closeSession method. The base method notifies the session handler, which may release the last reference to the session and destroy it.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 14:01 UTC
    CWE
    • Use After Free (CWE-416)
    • CWE-416 - Use After Free
    References
    Impacted products
    Vendor Product Version
    Facebook proxygen Affected: v2026.04.06.00 , < v2026.09.28.00 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "LOW",
                  "baseScore": 7.3,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "LOW",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84895",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T14:01:47.375791Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-416",
                    "description": "CWE-416 Use After Free",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T14:02:23.724Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "proxygen",
              "vendor": "Facebook",
              "versions": [
                {
                  "lessThan": "v2026.09.28.00",
                  "status": "affected",
                  "version": "v2026.04.06.00",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "dateAssigned": "2026-09-02T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSessionBase::closeSession method. The base method notifies the session handler, which may release the last reference to the session and destroy it."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Use After Free (CWE-416)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T20:44:34.886Z",
            "orgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
            "shortName": "Meta"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.facebook.com/security/advisories/cve-2026-84895"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/facebook/proxygen/commit/479eb5574195764e80e6cedebef669f6baa85083"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
        "assignerShortName": "Meta",
        "cveId": "CVE-2026-84895",
        "datePublished": "2026-09-28T20:44:34.886Z",
        "dateReserved": "2026-09-02T14:52:36.354Z",
        "dateUpdated": "2026-10-01T14:02:23.724Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-66707 (GCVE-0-2026-66707)

    Vulnerability from cvelistv5 – Published: 2026-08-06 14:28 – Updated: 2026-08-08 02:01
    VLAI
    Title
    WordPress Facebook for WooCommerce plugin <= 3.7.5 - Cross Site Scripting (XSS) vulnerability
    Summary
    Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-08 02:01 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    References
    Impacted products
    Vendor Product Version
    Facebook Facebook for WooCommerce Affected: n/a , ≤ 3.7.5 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-66707",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-08T02:01:06.216090Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-08T02:01:19.860Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "packageName": "facebook-for-woocommerce",
              "product": "Facebook for WooCommerce",
              "vendor": "Facebook",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "3.7.6",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "3.7.5",
                  "status": "affected",
                  "version": "n/a",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Rafie Muhammad | Patchstack Bug Bounty Program"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce \u003c= 3.7.5 versions."
                }
              ],
              "value": "Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce \u003c= 3.7.5 versions."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-591",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-591 Reflected XSS"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-06T14:28:08.911Z",
            "orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
            "shortName": "Patchstack"
          },
          "references": [
            {
              "tags": [
                "vdb-entry"
              ],
              "url": "https://patchstack.com/database/wordpress/plugin/facebook-for-woocommerce/vulnerability/wordpress-facebook-for-woocommerce-plugin-3-7-5-cross-site-scripting-xss-vulnerability?_s_id=cve"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Update the WordPress Facebook for WooCommerce Plugin to the latest available version (at least 3.7.6)."
                }
              ],
              "value": "Update the WordPress Facebook for WooCommerce Plugin to the latest available version (at least 3.7.6)."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "WordPress Facebook for WooCommerce plugin \u003c= 3.7.5 - Cross Site Scripting (XSS) vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
        "assignerShortName": "Patchstack",
        "cveId": "CVE-2026-66707",
        "datePublished": "2026-08-06T14:28:08.911Z",
        "dateReserved": "2026-07-27T14:01:16.156Z",
        "dateUpdated": "2026-08-08T02:01:19.860Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-66705 (GCVE-0-2026-66705)

    Vulnerability from cvelistv5 – Published: 2026-08-06 14:28 – Updated: 2026-08-06 15:04
    VLAI
    Title
    WordPress Facebook for WordPress plugin <= 5.2.1 - Cross Site Scripting (XSS) vulnerability
    Summary
    Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-06 15:03 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    References
    Impacted products
    Vendor Product Version
    Facebook Facebook for WordPress Affected: n/a , ≤ 5.2.1 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-66705",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-06T15:03:52.504021Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-06T15:04:00.807Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "packageName": "official-facebook-pixel",
              "product": "Facebook for WordPress",
              "vendor": "Facebook",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "5.2.2",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "5.2.1",
                  "status": "affected",
                  "version": "n/a",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Rafie Muhammad | Patchstack Bug Bounty Program"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress \u003c= 5.2.1 versions."
                }
              ],
              "value": "Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress \u003c= 5.2.1 versions."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-591",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-591 Reflected XSS"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-06T14:28:07.562Z",
            "orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
            "shortName": "Patchstack"
          },
          "references": [
            {
              "tags": [
                "vdb-entry"
              ],
              "url": "https://patchstack.com/database/wordpress/plugin/official-facebook-pixel/vulnerability/wordpress-facebook-for-wordpress-plugin-5-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Update the WordPress Facebook for WordPress Plugin to the latest available version (at least 5.2.2)."
                }
              ],
              "value": "Update the WordPress Facebook for WordPress Plugin to the latest available version (at least 5.2.2)."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "WordPress Facebook for WordPress plugin \u003c= 5.2.1 - Cross Site Scripting (XSS) vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
        "assignerShortName": "Patchstack",
        "cveId": "CVE-2026-66705",
        "datePublished": "2026-08-06T14:28:07.562Z",
        "dateReserved": "2026-07-27T14:01:16.156Z",
        "dateUpdated": "2026-08-06T15:04:00.807Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-44909 (GCVE-0-2026-44909)

    Vulnerability from cvelistv5 – Published: 2026-07-23 16:27 – Updated: 2026-07-23 19:07
    VLAI
    Summary
    Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW_SIZE to 0 or withholding WINDOW_UPDATE frames, causing the server to buffer complete response bodies in memory indefinitely for stalled streams. By opening many simultaneous streams requesting large resources while preventing the server from transmitting responses, an attacker could induce unbounded memory growth leading to service degradation, resource exhaustion, or denial of service. Versions v2017.01.16.00 through v2026.07.20.00 are affected.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-23 19:07 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    Facebook proxygen Affected: v2017.01.16.00 , < v2026.07.20.00 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-44909",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-23T19:07:17.371673Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-23T19:07:28.874Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "proxygen",
              "vendor": "Facebook",
              "versions": [
                {
                  "lessThan": "v2026.07.20.00",
                  "status": "affected",
                  "version": "v2017.01.16.00",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "dateAssigned": "2026-07-15T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW_SIZE to 0 or withholding WINDOW_UPDATE frames, causing the server to buffer complete response bodies in memory indefinitely for stalled streams. By opening many simultaneous streams requesting large resources while preventing the server from transmitting responses, an attacker could induce unbounded memory growth leading to service degradation, resource exhaustion, or denial of service. Versions v2017.01.16.00 through v2026.07.20.00 are affected."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "CWE-770",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-23T16:27:01.658Z",
            "orgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
            "shortName": "Meta"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/facebook/proxygen/commit/f28742f21f7022c261b7620d4e6b20d82b6cff72"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
        "assignerShortName": "Meta",
        "cveId": "CVE-2026-44909",
        "datePublished": "2026-07-23T16:27:01.658Z",
        "dateReserved": "2026-05-08T02:33:35.450Z",
        "dateUpdated": "2026-07-23T19:07:28.874Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-49059 (GCVE-0-2026-49059)

    Vulnerability from cvelistv5 – Published: 2026-05-27 14:33 – Updated: 2026-05-28 00:33 X_Open Source
    VLAI
    Title
    WordPress Facebook for WooCommerce plugin <= 3.7.0 - Open Redirection vulnerability
    Summary
    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Facebook Facebook for WooCommerce allows Phishing. This issue affects Facebook for WooCommerce: from n/a through 3.7.0.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-05-28 00:33 UTC
    CWE
    • CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')
    References
    Impacted products
    Vendor Product Version
    Facebook Facebook for WooCommerce Affected: n/a , ≤ 3.7.0 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-49059",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-05-28T00:33:31.656838Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-28T00:33:43.335Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "packageName": "facebook-for-woocommerce",
              "product": "Facebook for WooCommerce",
              "vendor": "Facebook",
              "versions": [
                {
                  "lessThanOrEqual": "3.7.0",
                  "status": "affected",
                  "version": "n/a",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "timomangcut | Patchstack Bug Bounty Program"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "URL Redirection to Untrusted Site (\u0027Open Redirect\u0027) vulnerability in Facebook Facebook for WooCommerce allows Phishing.\u003cp\u003eThis issue affects Facebook for WooCommerce: from n/a through 3.7.0.\u003c/p\u003e"
                }
              ],
              "value": "URL Redirection to Untrusted Site (\u0027Open Redirect\u0027) vulnerability in Facebook Facebook for WooCommerce allows Phishing.\n\nThis issue affects Facebook for WooCommerce: from n/a through 3.7.0."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-98",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-98 Phishing"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.7,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-601",
                  "description": "CWE-601 URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-27T14:33:18.844Z",
            "orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
            "shortName": "Patchstack"
          },
          "references": [
            {
              "tags": [
                "vdb-entry"
              ],
              "url": "https://patchstack.com/database/wordpress/plugin/facebook-for-woocommerce/vulnerability/wordpress-facebook-for-woocommerce-plugin-3-7-0-open-redirection-vulnerability?_s_id=cve"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "tags": [
            "x_open-source"
          ],
          "title": "WordPress Facebook for WooCommerce plugin \u003c= 3.7.0 - Open Redirection vulnerability",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
        "assignerShortName": "Patchstack",
        "cveId": "CVE-2026-49059",
        "datePublished": "2026-05-27T14:33:18.844Z",
        "dateReserved": "2026-05-27T10:26:36.700Z",
        "dateUpdated": "2026-05-28T00:33:43.335Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-23870 (GCVE-0-2026-23870)

    Vulnerability from cvelistv5 – Published: 2026-05-06 16:24 – Updated: 2026-05-06 19:06
    VLAI
    Summary
    A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.5, 19.1.0 through 19.1.6, and 19.2.0 through 19.2.5).
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-05-06 19:03 UTC
    CWE
    • (CWE-502) Deserialization of Untrusted Data, (CWE-400) Uncontrolled Resource Consumption
    References
    Impacted products
    Vendor Product Version
    Meta react-server-dom-turbopack Affected: 19.0.0 , ≤ 19.0.5 (semver)
    Affected: 19.1.0 , ≤ 19.1.6 (semver)
    Affected: 19.2.0 , ≤ 19.2.5 (semver)
    Create a notification for this product.
    Meta react-server-dom-parcel Affected: 19.0.0 , ≤ 19.0.5 (semver)
    Affected: 19.1.0 , ≤ 19.1.6 (semver)
    Affected: 19.2.0 , ≤ 19.2.5 (semver)
    Create a notification for this product.
    Meta react-server-dom-webpack Affected: 19.0.0 , ≤ 19.0.5 (semver)
    Affected: 19.1.0 , ≤ 19.1.6 (semver)
    Affected: 19.2.0 , ≤ 19.2.5 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-23870",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-05-06T19:03:16.700440Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-06T19:06:00.435Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-turbopack",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.5",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.6",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.5",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-parcel",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.5",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.6",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.5",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-webpack",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.5",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.6",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.5",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "dateAssigned": "2026-05-06T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.5, 19.1.0 through 19.1.6, and 19.2.0 through 19.2.5)."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "(CWE-502) Deserialization of Untrusted Data, (CWE-400) Uncontrolled Resource Consumption",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-06T16:24:55.620Z",
            "orgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
            "shortName": "Meta"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/facebook/react/security/advisories/GHSA-rv78-f8rc-xrxh"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
        "assignerShortName": "Meta",
        "cveId": "CVE-2026-23870",
        "datePublished": "2026-05-06T16:24:55.620Z",
        "dateReserved": "2026-01-16T19:49:26.309Z",
        "dateUpdated": "2026-05-06T19:06:00.435Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-23866 (GCVE-0-2026-23866)

    Vulnerability from cvelistv5 – Published: 2026-05-01 16:02 – Updated: 2026-05-01 17:42
    VLAI
    Summary
    Incomplete validation of AI rich response messages for Instagram Reels in WhatsApp for iOS v2.25.8.0 to v2.26.15.72 and WhatsApp for Android v2.25.8.0 to v2.26.7.10 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device, including triggering OS-controlled custom URL scheme handlers. We have not seen evidence of exploitation in the wild.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-05-01 17:41 UTC
    CWE
    • Improper Verification of Source of a Communication Channel (CWE-940)
    • CWE-940 - Improper Verification of Source of a Communication Channel
    References
    Impacted products
    Vendor Product Version
    Facebook WhatsApp for Android Affected: 2.25.8.0 , < 2.26.7.10 (semver)
    Create a notification for this product.
    Facebook WhatsApp for iOS Affected: 2.25.8.0 , < 2.26.15.72 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-23866",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-05-01T17:41:43.060585Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-940",
                    "description": "CWE-940 Improper Verification of Source of a Communication Channel",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-01T17:42:09.286Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WhatsApp for Android",
              "vendor": "Facebook",
              "versions": [
                {
                  "lessThan": "2.26.7.10",
                  "status": "affected",
                  "version": "2.25.8.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "WhatsApp for iOS",
              "vendor": "Facebook",
              "versions": [
                {
                  "lessThan": "2.26.15.72",
                  "status": "affected",
                  "version": "2.25.8.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "dateAssigned": "2026-04-20T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Incomplete validation of AI rich response messages for Instagram Reels in WhatsApp for iOS v2.25.8.0 to v2.26.15.72 and WhatsApp for Android v2.25.8.0 to v2.26.7.10 could have allowed a user to trigger processing of media content from an arbitrary URL on another user\u2019s device, including triggering OS-controlled custom URL scheme handlers. We have not seen evidence of exploitation in the wild."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:F/RL:O/RC:C",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Improper Verification of Source of a Communication Channel (CWE-940)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-01T16:10:25.306Z",
            "orgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
            "shortName": "Meta"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.facebook.com/security/advisories/cve-2026-23866"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.whatsapp.com/security/advisories/2026"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
        "assignerShortName": "Meta",
        "cveId": "CVE-2026-23866",
        "datePublished": "2026-05-01T16:02:03.304Z",
        "dateReserved": "2026-01-16T19:49:26.309Z",
        "dateUpdated": "2026-05-01T17:42:09.286Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-23863 (GCVE-0-2026-23863)

    Vulnerability from cvelistv5 – Published: 2026-05-01 16:01 – Updated: 2026-05-01 17:41
    VLAI
    Summary
    An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously formatted documents with embedded NUL bytes in the filename to be shown in the application as one type of file but run as an executable when opened. We have not seen evidence of exploitation in the wild.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-05-01 17:40 UTC
    CWE
    • Improper Neutralization of Null Byte or NUL Character (CWE-158)
    • CWE-158 - Improper Neutralization of Null Byte or NUL Character
    References
    Impacted products
    Vendor Product Version
    Facebook WhatsApp Desktop for Windows Affected: 2.3000.*.252500 , < 2.3000.1032164386.258709 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-23863",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-05-01T17:40:45.569668Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-158",
                    "description": "CWE-158 Improper Neutralization of Null Byte or NUL Character",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-01T17:41:14.681Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "WhatsApp Desktop for Windows",
              "vendor": "Facebook",
              "versions": [
                {
                  "lessThan": "2.3000.1032164386.258709",
                  "status": "affected",
                  "version": "2.3000.*.252500",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "dateAssigned": "2026-04-20T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously formatted documents with embedded NUL bytes in the filename to be shown in the application as one type of file but run as an executable when opened. We have not seen evidence of exploitation in the wild."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:F/RL:O/RC:C",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Improper Neutralization of Null Byte or NUL Character (CWE-158)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-01T16:15:38.171Z",
            "orgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
            "shortName": "Meta"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.facebook.com/security/advisories/cve-2026-23863"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.whatsapp.com/security/advisories/2026"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
        "assignerShortName": "Meta",
        "cveId": "CVE-2026-23863",
        "datePublished": "2026-05-01T16:01:39.565Z",
        "dateReserved": "2026-01-16T19:49:26.308Z",
        "dateUpdated": "2026-05-01T17:41:14.681Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-23864 (GCVE-0-2026-23864)

    Vulnerability from cvelistv5 – Published: 2026-01-26 19:16 – Updated: 2026-07-15 01:18
    VLAI
    Summary
    Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending specially crafted HTTP requests to Server Function endpoints, and could lead to server crashes, out-of-memory exceptions or excessive CPU usage; depending on the vulnerable code path being exercised, the application configuration and application code. Strongly consider upgrading to the latest package versions to reduce risk and prevent availability issues in applications using React Server Components.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-01-26 20:26 UTC
    CWE
    • (CWE-502): Deserialization of Untrusted Data. (CWE-400): Uncontrolled Resource Consumption
    • CWE-502 - Deserialization of Untrusted Data
    • CWE-400 - Uncontrolled Resource Consumption
    • CWE-1284 - Improper Validation of Specified Quantity in Input
    References
    Impacted products
    Vendor Product Version
    Meta react-server-dom-webpack Affected: 19.0.0 , < 19.0.4 (semver)
    Affected: 19.1.0 , < 19.1.5 (semver)
    Affected: 19.2.0 , < 19.2.4 (semver)
    Create a notification for this product.
    Meta react-server-dom-turbopack Affected: 19.0.0 , < 19.0.4 (semver)
    Affected: 19.1.0 , < 19.1.5 (semver)
    Affected: 19.2.0 , < 19.2.4 (semver)
    Create a notification for this product.
    Meta react-server-dom-parcel Affected: 19.0.0 , < 19.0.4 (semver)
    Affected: 19.1.0 , < 19.1.5 (semver)
    Affected: 19.2.0 , < 19.2.4 (semver)
    Create a notification for this product.
    Red Hat Streams for Apache Kafka 2.9.4     cpe:/a:redhat:amq_streams:2.9::el9
    Create a notification for this product.
    Red Hat Streams for Apache Kafka 3.2.0     cpe:/a:redhat:amq_streams:3.2::el9
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-23864",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-01-26T20:26:03.428817Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-502",
                    "description": "CWE-502 Deserialization of Untrusted Data",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              },
              {
                "descriptions": [
                  {
                    "cweId": "CWE-400",
                    "description": "CWE-400 Uncontrolled Resource Consumption",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-01-26T20:26:45.709Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "affected": [
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/a:redhat:amq_streams:2.9::el9"
                ],
                "defaultStatus": "unaffected",
                "packageName": "com.github.streamshub-console",
                "product": "Streams for Apache Kafka 2.9.4",
                "vendor": "Red Hat"
              },
              {
                "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
                "cpes": [
                  "cpe:/a:redhat:amq_streams:3.2::el9"
                ],
                "defaultStatus": "unaffected",
                "packageName": "com.github.streamshub-console",
                "product": "Streams for Apache Kafka 3.2.0",
                "vendor": "Red Hat"
              }
            ],
            "datePublic": "2026-01-26T19:16:38.250Z",
            "descriptions": [
              {
                "lang": "en",
                "value": "A flaw was found in React Server Components. A remote attacker can exploit this vulnerability by sending specially crafted HTTP requests to Server Function endpoints. This can lead to a Denial of Service (DoS), causing server crashes, out-of-memory exceptions, or excessive CPU usage, thereby impacting the availability of applications."
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "namespace": "https://access.redhat.com/security/updates/classification/",
                    "value": "Important"
                  },
                  "type": "Red Hat severity rating"
                }
              },
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.5,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                },
                "format": "CVSS"
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-1284",
                    "description": "Improper Validation of Specified Quantity in Input",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-15T01:18:01.838Z",
              "orgId": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
              "shortName": "redhat-SADP"
            },
            "references": [
              {
                "tags": [
                  "vdb-entry",
                  "x_refsource_REDHAT"
                ],
                "url": "https://access.redhat.com/security/cve/CVE-2026-23864"
              },
              {
                "name": "RHBZ#2433059",
                "tags": [
                  "issue-tracking",
                  "x_refsource_REDHAT"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433059"
              },
              {
                "tags": [
                  "x_sadp-csaf-vex"
                ],
                "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23864.json"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2026:34608"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2026:13571"
              }
            ],
            "solutions": [
              {
                "lang": "en",
                "value": "RHSA-2026:34608: Streams for Apache Kafka 2.9.4"
              },
              {
                "lang": "en",
                "value": "RHSA-2026:13571: Streams for Apache Kafka 3.2.0"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2026-01-26T20:01:54.396Z",
                "value": "Reported to Red Hat."
              },
              {
                "lang": "en",
                "time": "2026-01-26T19:16:38.250Z",
                "value": "Made public."
              }
            ],
            "title": "react-server-dom-webpack: react-server-dom-parcel: reactreact-server-dom-turbopack: React Server Components: Denial of Service via specially crafted HTTP requests",
            "x_adpType": "supplier",
            "x_generator": {
              "engine": "sadp-cli 1.0.0"
            }
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-webpack",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThan": "19.0.4",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "19.1.5",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "19.2.4",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-turbopack",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThan": "19.0.4",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "19.1.5",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "19.2.4",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-parcel",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThan": "19.0.4",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "19.1.5",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "19.2.4",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack.\n\nThe vulnerabilities are triggered by sending specially crafted HTTP requests to Server Function endpoints, and could lead to server crashes, out-of-memory exceptions or excessive CPU usage; depending on the vulnerable code path being exercised, the application configuration and application code.\n\nStrongly consider upgrading to the latest package versions to reduce risk and prevent availability issues in applications using React Server Components."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "(CWE-502): Deserialization of Untrusted Data. (CWE-400): Uncontrolled Resource Consumption",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-01-26T19:16:38.250Z",
            "orgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
            "shortName": "Meta"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.facebook.com/security/advisories/cve-2026-23864"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
        "assignerShortName": "Meta",
        "cveId": "CVE-2026-23864",
        "datePublished": "2026-01-26T19:16:38.250Z",
        "dateReserved": "2026-01-16T19:49:26.309Z",
        "dateUpdated": "2026-07-15T01:18:01.838Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-67779 (GCVE-0-2025-67779)

    Vulnerability from cvelistv5 – Published: 2025-12-11 23:36 – Updated: 2025-12-12 18:40
    VLAI
    Summary
    It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe deserialization of payloads from HTTP requests to Server Function endpoints. This can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-12-12 18:39 UTC
    CWE
    • (CWE-502) Deserialization of Untrusted Data, (CWE-400) Uncontrolled Resource Consumption
    • CWE-502 - Deserialization of Untrusted Data
    • CWE-400 - Uncontrolled Resource Consumption
    References
    Impacted products
    Vendor Product Version
    Meta react-server-dom-parcel Affected: 19.0.2 , ≤ 19.0.2 (semver)
    Affected: 19.1.3 , ≤ 19.1.3 (semver)
    Affected: 19.2.2 , ≤ 19.2.2 (semver)
    Create a notification for this product.
    Meta react-server-dom-turbopack Affected: 19.0.2 , ≤ 19.0.2 (semver)
    Affected: 19.1.3 , ≤ 19.1.3 (semver)
    Affected: 19.2.2 , ≤ 19.2.2 (semver)
    Create a notification for this product.
    Meta react-server-dom-webpack Affected: 19.0.2 , ≤ 19.0.2 (semver)
    Affected: 19.1.3 , ≤ 19.1.3 (semver)
    Affected: 19.2.2 , ≤ 19.2.2 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-67779",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-12-12T18:39:24.796538Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-502",
                    "description": "CWE-502 Deserialization of Untrusted Data",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              },
              {
                "descriptions": [
                  {
                    "cweId": "CWE-400",
                    "description": "CWE-400 Uncontrolled Resource Consumption",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-12-12T18:40:45.863Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-parcel",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.2",
                  "status": "affected",
                  "version": "19.0.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.3",
                  "status": "affected",
                  "version": "19.1.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.2",
                  "status": "affected",
                  "version": "19.2.2",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-turbopack",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.2",
                  "status": "affected",
                  "version": "19.0.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.3",
                  "status": "affected",
                  "version": "19.1.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.2",
                  "status": "affected",
                  "version": "19.2.2",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-webpack",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.2",
                  "status": "affected",
                  "version": "19.0.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.3",
                  "status": "affected",
                  "version": "19.1.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.2",
                  "status": "affected",
                  "version": "19.2.2",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "dateAssigned": "2025-12-11T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe deserialization of payloads from HTTP requests to Server Function endpoints. This can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "(CWE-502) Deserialization of Untrusted Data, (CWE-400) Uncontrolled Resource Consumption",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-12-11T23:36:20.699Z",
            "orgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
            "shortName": "Meta"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.facebook.com/security/advisories/cve-2025-67779"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
        "assignerShortName": "Meta",
        "cveId": "CVE-2025-67779",
        "datePublished": "2025-12-11T23:36:20.699Z",
        "dateReserved": "2025-12-11T22:58:08.827Z",
        "dateUpdated": "2025-12-12T18:40:45.863Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-55184 (GCVE-0-2025-55184)

    Vulnerability from cvelistv5 – Published: 2025-12-11 20:05 – Updated: 2025-12-15 16:37
    VLAI
    Summary
    A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints, which can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-12-15 16:36 UTC
    CWE
    • (CWE-502) Deserialization of Untrusted Data. (CWE-400) Uncontrolled Resource Consumption
    Impacted products
    Vendor Product Version
    Meta react-server-dom-webpack Affected: 19.0.0 , ≤ 19.0.1 (semver)
    Affected: 19.1.0 , ≤ 19.1.2 (semver)
    Affected: 19.2.0 , ≤ 19.2.1 (semver)
    Create a notification for this product.
    Meta react-server-dom-turbopack Affected: 19.0.0 , ≤ 19.0.1 (semver)
    Affected: 19.1.0 , ≤ 19.1.2 (semver)
    Affected: 19.2.0 , ≤ 19.2.1 (semver)
    Create a notification for this product.
    Meta react-server-dom-parcel Affected: 19.0.0 , ≤ 19.0.1 (semver)
    Affected: 19.1.0 , ≤ 19.1.2 (semver)
    Affected: 19.2.0 , ≤ 19.2.1 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-55184",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-12-15T16:36:27.831763Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-12-15T16:37:06.708Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/KingHacker353/CVE-2025-55184"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-webpack",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.1",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.2",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.1",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-turbopack",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.1",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.2",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.1",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-parcel",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.1",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.2",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.1",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "dateAssigned": "2025-12-09T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints, which can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "(CWE-502) Deserialization of Untrusted Data. (CWE-400) Uncontrolled Resource Consumption",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-12-11T20:11:26.262Z",
            "orgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
            "shortName": "Meta"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.facebook.com/security/advisories/cve-2025-55184"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
        "assignerShortName": "Meta",
        "cveId": "CVE-2025-55184",
        "datePublished": "2025-12-11T20:05:01.328Z",
        "dateReserved": "2025-08-08T18:21:47.119Z",
        "dateUpdated": "2025-12-15T16:37:06.708Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-55183 (GCVE-0-2025-55183)

    Vulnerability from cvelistv5 – Published: 2025-12-11 20:04 – Updated: 2026-01-07 16:26
    VLAI
    Summary
    An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. A specifically crafted HTTP request sent to a vulnerable Server Function may unsafely return the source code of any Server Function. Exploitation requires the existence of a Server Function which explicitly or implicitly exposes a stringified argument.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-01-07 16:24 UTC
    CWE
    • (CWE-502) Deserialization of Untrusted Data. (CWE-497) Exposure of Sensitive System Information to an Unauthorized Actor
    References
    Impacted products
    Vendor Product Version
    Meta react-server-dom-webpack Affected: 19.0.0 , ≤ 19.0.1 (semver)
    Affected: 19.1.0 , ≤ 19.1.2 (semver)
    Affected: 19.2.0 , ≤ 19.2.1 (semver)
    Create a notification for this product.
    Meta react-server-dom-turbopack Affected: 19.0.0 , ≤ 19.0.1 (semver)
    Affected: 19.1.0 , ≤ 19.1.2 (semver)
    Affected: 19.2.0 , ≤ 19.2.1 (semver)
    Create a notification for this product.
    Meta react-server-dom-parcel Affected: 19.0.0 , ≤ 19.0.1 (semver)
    Affected: 19.1.0 , ≤ 19.1.2 (semver)
    Affected: 19.2.0 , ≤ 19.2.1 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-55183",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-01-07T16:24:47.971492Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-01-07T16:26:47.826Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-webpack",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.1",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.2",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.1",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-turbopack",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.1",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.2",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.1",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-parcel",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.1",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.2",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.1",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "dateAssigned": "2025-12-09T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. A specifically crafted HTTP request sent to a vulnerable Server Function may unsafely return the source code of any Server Function. Exploitation requires the existence of a Server Function which explicitly or implicitly exposes a stringified argument."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "(CWE-502) Deserialization of Untrusted Data. (CWE-497) Exposure of Sensitive System Information to an Unauthorized Actor",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-12-11T20:09:32.286Z",
            "orgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
            "shortName": "Meta"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.facebook.com/security/advisories/cve-2025-55183"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
        "assignerShortName": "Meta",
        "cveId": "CVE-2025-55183",
        "datePublished": "2025-12-11T20:04:48.655Z",
        "dateReserved": "2025-08-08T18:21:47.119Z",
        "dateUpdated": "2026-01-07T16:26:47.826Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-55182 (GCVE-0-2025-55182)

    Vulnerability from cvelistv5 – Published: 2025-12-03 15:40 – Updated: 2026-08-04 03:56
    VLAI CISA ENISA Previdian
    Summary
    A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
    SSVC
    Exploitation: active Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-12-03 00:00 UTC
    CWE
    • Deserialization of Untrusted Data (CWE-502)
    Impacted products
    Vendor Product Version
    Meta react-server-dom-webpack Affected: 19.0.0 , ≤ 19.0.0 (semver)
    Affected: 19.1.0 , ≤ 19.1.1 (semver)
    Affected: 19.2.0 , ≤ 19.2.0 (semver)
    Create a notification for this product.
    Meta react-server-dom-turbopack Affected: 19.0.0 , ≤ 19.0.0 (semver)
    Affected: 19.1.0 , ≤ 19.1.1 (semver)
    Affected: 19.2.0 , ≤ 19.2.0 (semver)
    Create a notification for this product.
    Meta react-server-dom-parcel Affected: 19.0.0 , ≤ 19.0.0 (semver)
    Affected: 19.1.0 , ≤ 19.1.1 (semver)
    Affected: 19.2.0 , ≤ 19.2.0 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-55182",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-12-03T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2025-12-05",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-55182"
                  },
                  "type": "kev"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-04T03:56:01.281Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "media-coverage"
                ],
                "url": "https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/"
              },
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-55182"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2025-12-05T00:00:00.000Z",
                "value": "CVE-2025-55182 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-12-04T17:32:12.884Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "http://www.openwall.com/lists/oss-security/2025/12/03/4"
              },
              {
                "url": "https://news.ycombinator.com/item?id=46136026"
              }
            ],
            "title": "CVE Program Container",
            "x_generator": {
              "engine": "ADPogram 0.0.1"
            }
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-webpack",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.0",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.1",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.0",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-turbopack",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.0",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.1",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.0",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "react-server-dom-parcel",
              "vendor": "Meta",
              "versions": [
                {
                  "lessThanOrEqual": "19.0.0",
                  "status": "affected",
                  "version": "19.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.1.1",
                  "status": "affected",
                  "version": "19.1.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "19.2.0",
                  "status": "affected",
                  "version": "19.2.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "dateAssigned": "2025-12-02T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 10,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Deserialization of Untrusted Data (CWE-502)",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-12-11T20:15:37.699Z",
            "orgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
            "shortName": "Meta"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.facebook.com/security/advisories/cve-2025-55182"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
        "assignerShortName": "Meta",
        "cveId": "CVE-2025-55182",
        "datePublished": "2025-12-03T15:40:56.894Z",
        "dateReserved": "2025-08-08T18:21:47.119Z",
        "dateUpdated": "2026-08-04T03:56:01.281Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }