GHSA-w94c-4vhp-22gx

Suggest an improvement
Source
https://github.com/advisories/GHSA-w94c-4vhp-22gx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-w94c-4vhp-22gx/GHSA-w94c-4vhp-22gx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-w94c-4vhp-22gx
Published
2026-05-11T14:50:36Z
Modified
2026-05-11T15:04:26Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
@vitejs/plugin-rsc has a Denial of Service Vulnerability in React Server Components
Details

Impact

@vitejs/plugin-rsc vendors react-server-dom-webpack, which contained a vulnerability in versions prior to 19.2.6. See details in React repository's advisory https://github.com/facebook/react/security/advisories/GHSA-rv78-f8rc-xrxh

Patches

Upgrade immediately to @vitejs/plugin-rsc@0.5.26 or later.

Database specific
{
    "cwe_ids":  [
        "CWE-770"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-05-11T14:50:36Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / @vitejs/plugin-rsc

Package

Name
@vitejs/plugin-rsc
View open source insights on deps.dev
Purl
pkg:npm/%40vitejs/plugin-rsc

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.5.26

Database specific

last_known_affected_version_range
"<= 0.5.25"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-w94c-4vhp-22gx/GHSA-w94c-4vhp-22gx.json"