Skip to content
React Server Components Vulnerability Allows DoS Attacks on Next.js Servers

React Server Components Vulnerability Allows DoS Attacks on Next.js Servers

First seen 9 Oct 2026, 15:40 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 9, 2026 at 16:35 UTC
  • •CVE-2026-23870 allows DoS attacks on Next.js servers via crafted POST requests.
  • •The vulnerability affects React 19.x versions, specifically 19.0.0 to 19.2.5.
  • •Attackers can exploit this flaw without authentication if endpoints are public.

A high-severity vulnerability (CVE-2026-23870) in React Server Components enables attackers to freeze Next.js servers by sending specially crafted HTTP POST requests. This flaw affects React 19.x versions and can lead to denial-of-service conditions due to excessive CPU consumption. The vulnerability arises from the handling of multipart form data during server-side function invocations, resulting in quadratic processing overhead. Attackers can exploit this vulnerability without requiring authentication if the Server Action endpoint is publicly accessible. The affected packages include react-server-dom-webpack, react-server-dom-turbopack, and react-server-dom-parcel, specifically in versions 19.0.0 to 19.2.5. Organizations using these components are advised to implement mitigations immediately.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-05-06
CVE-2026-23870 published
A high-severity denial-of-service vulnerability in React Server Components was disclosed.
Gbhackers
2026-05-13
First public PoC released
Proof-of-concept code demonstrating the exploit was made public, increasing risk of exploitation.
Gbhackers

More articles in this cluster (2)

Following this threat?

Track CVE-2026-23870 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of React are affected?
Versions 19.0.0 through 19.2.5 of React are affected by this vulnerability.
What is the impact of this vulnerability?
The vulnerability can lead to denial-of-service conditions, freezing servers due to excessive CPU usage.
What should organizations do to mitigate this risk?
Organizations should review their use of affected React Server Components and implement necessary mitigations immediately.