An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. A specifically crafted HTTP request sent to a vulnerable Server Function may unsafely return the source code of any Server Function. Exploitation requires the existence of a Server Function which explicitly or implicitly exposes a stringified argument.
{
"versions": [
{
"introduced": "19.0.0"
},
{
"fixed": "19.0.2"
},
{
"introduced": "19.1.0"
},
{
"fixed": "19.1.3"
},
{
"introduced": "19.2.0"
},
{
"fixed": "19.2.2"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "16.1.0-NA"
}
]
}{
"versions": [
{
"introduced": "15.0.0"
},
{
"fixed": "15.0.7"
},
{
"introduced": "15.1.0"
},
{
"fixed": "15.1.11"
},
{
"introduced": "15.2.0"
},
{
"fixed": "15.2.8"
},
{
"introduced": "15.3.0"
},
{
"fixed": "15.3.8"
},
{
"introduced": "15.4.0"
},
{
"fixed": "15.4.10"
},
{
"introduced": "15.5.0"
},
{
"fixed": "15.5.9"
},
{
"introduced": "16.0.0"
},
{
"fixed": "16.0.10"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary0"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary1"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary10"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary11"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary12"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary13"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary14"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary15"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary16"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary17"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary18"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary19"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary2"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary20"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary21"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary22"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary23"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary24"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary25"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary26"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary27"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary28"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary29"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary3"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary30"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary31"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary32"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary33"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary34"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary35"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary36"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary37"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary38"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary39"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary4"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary40"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary41"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary42"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary43"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary44"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary45"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary46"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary47"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary48"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary49"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary5"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary50"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary51"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary52"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary53"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary54"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary55"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary56"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary57"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary58"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary59"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary6"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary7"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary8"
},
{
"introduced": "0"
},
{
"last_affected": "15.6.0-canary9"
},
{
"introduced": "0"
},
{
"last_affected": "16.1.0-canary0"
},
{
"introduced": "0"
},
{
"last_affected": "16.1.0-canary1"
},
{
"introduced": "0"
},
{
"last_affected": "16.1.0-canary10"
},
{
"introduced": "0"
},
{
"last_affected": "16.1.0-canary11"
},
{
"introduced": "0"
},
{
"last_affected": "16.1.0-canary12"
},
{
"introduced": "0"
},
{
"last_affected": "16.1.0-canary13"
},
{
"introduced": "0"
},
{
"last_affected": "16.1.0-canary14"
},
{
"introduced": "0"
},
{
"last_affected": "16.1.0-canary15"
},
{
"introduced": "0"
},
{
"last_affected": "16.1.0-canary16"
},
{
"introduced": "0"
},
{
"last_affected": "16.1.0-canary17"
},
{
"introduced": "0"
},
{
"last_affected": "16.1.0-canary18"
},
{
"introduced": "0"
},
{
"last_affected": "16.1.0-canary2"
},
{
"introduced": "0"
},
{
"last_affected": "16.1.0-canary3"
},
{
"introduced": "0"
},
{
"last_affected": "16.1.0-canary4"
},
{
"introduced": "0"
},
{
"last_affected": "16.1.0-canary5"
},
{
"introduced": "0"
},
{
"last_affected": "16.1.0-canary6"
},
{
"introduced": "0"
},
{
"last_affected": "16.1.0-canary7"
},
{
"introduced": "0"
},
{
"last_affected": "16.1.0-canary8"
},
{
"introduced": "0"
},
{
"last_affected": "16.1.0-canary9"
}
]
}