Gbhackers React Server Components Vulnerability Allows DoS Attacks on Next.js Servers
Article Content
- •CVE-2026-23870 allows DoS attacks on Next.js servers via crafted POST requests.
- •The vulnerability affects React 19.x versions, specifically 19.0.0 to 19.2.5.
- •Attackers can exploit this flaw without authentication if endpoints are public.
A high-severity vulnerability (CVE-2026-23870) in React Server Components enables attackers to freeze Next.js servers by sending specially crafted HTTP POST requests. This flaw affects React 19.x versions and can lead to denial-of-service conditions due to excessive CPU consumption. The vulnerability arises from the handling of multipart form data during server-side function invocations, resulting in quadratic processing overhead. Attackers can exploit this vulnerability without requiring authentication if the Server Action endpoint is publicly accessible. The affected packages include react-server-dom-webpack, react-server-dom-turbopack, and react-server-dom-parcel, specifically in versions 19.0.0 to 19.2.5. Organizations using these components are advised to implement mitigations immediately.
Ask AI about this cluster
Answers cite the sources they use
More articles in this cluster (2)
Following this threat?
Track CVE-2026-23870 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of React are affected?
What is the impact of this vulnerability?
What should organizations do to mitigate this risk?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Sets Oct. 11 Deadline for Patching Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after they were exploited by the China-linked group Flax Typhoon. Federal agencies must patch or retire the affected software by October 11, 2026. The vulnerabilities…