highCVSS 7.5Vulnerability

GHSA-w94c-4vhp-22gx

### Impact `@vitejs/plugin-rsc` vendors `react-server-dom-webpack`, which contained a vulnerability in versions prior to 19.2.6. See details in React repository's advisory https://github.com/facebook/react/security/advisories/GHSA-rv78-f8rc-xrxh ### Patches Upgrade immediately to `@vitejs/[email protected]` or later.

Properties

ghsa_id
GHSA-w94c-4vhp-22gx
summary
@vitejs/plugin-rsc has a Denial of Service Vulnerability in React Server Components
severity
high
cvss_score
7.5
cve_id
GHSA-w94c-4vhp-22gx
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
is_ghsa_only
true
ghsa_published
2026-05-11T14:50:36Z
source_url
https://github.com/advisories/GHSA-w94c-4vhp-22gx
ghsa_updated
2026-05-11T14:50:38Z

Related Entities (4)

AFFECTS (1)

[Software]npm/@vitejs/plugin-rsc

HAS_WEAKNESS (1)

[Weakness]Allocation of Resources Without Limits or Throttling

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/@vitejs/plugin-rsc

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-w94c-4vhp-22gx (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal