highCVSS 7.5Vulnerability
GHSA-w94c-4vhp-22gx
### Impact `@vitejs/plugin-rsc` vendors `react-server-dom-webpack`, which contained a vulnerability in versions prior to 19.2.6. See details in React repository's advisory https://github.com/facebook/react/security/advisories/GHSA-rv78-f8rc-xrxh ### Patches Upgrade immediately to `@vitejs/[email protected]` or later.
Properties
- ghsa_id
- GHSA-w94c-4vhp-22gx
- summary
- @vitejs/plugin-rsc has a Denial of Service Vulnerability in React Server Components
- severity
- high
- cvss_score
- 7.5
- cve_id
- GHSA-w94c-4vhp-22gx
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- is_ghsa_only
- true
- ghsa_published
- 2026-05-11T14:50:36Z
- source_url
- https://github.com/advisories/GHSA-w94c-4vhp-22gx
- ghsa_updated
- 2026-05-11T14:50:38Z
Related Entities (4)
AFFECTS (1)
→[Software]npm/@vitejs/plugin-rsc
HAS_WEAKNESS (1)
→[Weakness]Allocation of Resources Without Limits or Throttling
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]npm/@vitejs/plugin-rsc
Explore deeper with Ninja Signal's threat intelligence graph