React Server Components Flaw Lets Attackers Freeze Next.js Servers With a Single POST Request
CVE-2026-23870 lets attackers freeze vulnerable Next.js servers with one crafted POST to React Server Functions.
CVE-2026-23870 is a high-severity denial-of-service flaw (CVSS 7.5, CWE-400) in React Server Components used by React 19 and many Next.js apps. A remote attacker can send one crafted POST to a Server Function endpoint, forcing repeated form-field scans that consume CPU and can freeze Node.js servers before application logic runs. Researcher Simon Koeck’s proof of concept showed a roughly 900 KB request could trigger about 100 million string comparisons. Affected ranges are 19.0.0–19.0.5, 19.1.0–19.1.6, and 19.2.0–19.2.5, fixed in 19.0.6, 19.1.7, and 19.2.6.
- CVE-2026-23870 is a CVSS 7.5 React Server Components denial-of-service flaw.
- Crafted POSTs with many $K references can exhaust CPU and stall Node.js.
- Affects React 19.0.0–19.0.5, 19.1.0–19.1.6, and 19.2.0–19.2.5.
- Fixed in 19.0.6, 19.1.7, and 19.2.6; Next.js users should verify dependencies.
Vulnerabilities mentionedAll →
- CVE-2026-238707.52%A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server…published · facebook react-server-dom-parcel
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-23870 | A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server… A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.5, 19.1.0 through 19.1.6, and 19.2.0 through 19.2.5). |
Full article749 words · extracted from cybersecuritynews.com · click to collapse
A high-severity denial-of-service flaw (CVE-2026-23870) in React Server Components can allow a remote attacker to freeze vulnerable Next.js servers by sending a specially crafted POST request to a Server Function endpoint.
The issue has a CVSS score of 7.5 and affects React Server Components packages used by React 19.x applications, including many Next.js deployments using Server Actions.
The vulnerability stems from the way React rebuilds submitted form data before a Server Action runs. An attacker does not need to break into the application or access protected data.
Instead, they can force the server to run many repeated checks, consume CPU resources, and stop it from responding to normal visitors.
React fixed the flaw in versions 19.0.6, 19.1.7, and 19.2.6. Organizations running older releases should upgrade as soon as possible.
Modern React applications use Server Actions to let form submissions call backend functions directly, requiring React to parse HTTP requests and reconstruct submitted form fields before execution.
The vulnerable code handles special references inside React’s form-data format. One reference type, marked with $K, tells React that a nested form structure needs to be rebuilt. To resolve each $K reference, React created a list of every field in the submitted request and then checked the full list for matching entries.
That logic becomes expensive when a request contains a large number of references and a large number of ordinary fields. Each $K reference triggers another full scan of the submitted field list. For example, a POST request containing 10,000 references and 10,000 form fields can cause roughly 100 million string comparisons.
React Server Components Flaw
A proof-of-concept shared by researcher Simon Koeck showed that a request of about 900 KB could trigger this workload. The issue is not the request size itself, but the repeated processing React performs when handling the submitted data structure.
Many Next.js deployments run on Node.js, where CPU-heavy synchronous processing can block the event loop. While React scans the attacker-controlled form fields, the server may be unable to process other incoming requests in time.
As a result, legitimate users may experience slow page loads, request timeouts, or HTTP 503 errors. Repeated malicious POST requests could keep an application instance unavailable long enough for health checks or load balancers to mark it unhealthy and remove it from service.
The vulnerability matters because parsing happens before the application’s Server Action logic runs. In practice, protections implemented inside the action itself do not prevent costly request parsing.
Publicly reachable Server Actions are the most exposed, but authenticated applications can also be affected when any normal user can reach the vulnerable endpoint.
React’s advisory says specially crafted HTTP requests to server function endpoints can lead to excessive CPU usage, out-of-memory conditions, or server crashes. NIST classifies the issue as CWE-400, or uncontrolled resource consumption.
CVE-2026-23870 affects the following React Server Components packages:
react-server-dom-webpack, react-server-dom-turbopack, and react-server-dom-parcel.
The vulnerable version ranges are React 19.0.0 through 19.0.5, React 19.1.0 through 19.1.6, and React 19.2.0 through 19.2.5. The patched releases are 19.0.6, 19.1.7, and 19.2.6.
Next.js users should check their resolved dependency tree rather than relying only on the top-level Next.js version. Applications using the App Router, React Server Components, or Server Actions may include one of the affected React server-dom packages through their framework dependencies.
Cyber Security News previously reported that the broader React and Next.js issue set affected App Router deployments and Server Function endpoints, making dependency verification important for development and production teams.
React changed the affected form-data processing path so fields are scanned once and consumed as they are handled, rather than rescanning the complete list for every nested reference. This removes the repeated-work condition behind the CPU exhaustion issue.
Teams should update React and the relevant React Server Components packages to the fixed release in their supported branch, rebuild application artifacts, and redeploy all affected environments.
They should also review edge and reverse-proxy controls, including POST body-size limits, request-rate controls, and timeouts. These controls can reduce exposure, but patching React remains the primary fix because the weakness exists in React’s request-processing logic.
Administrators should monitor for unusual POST activity against pages that expose Server Actions, especially bursts of multipart form-data requests, high CPU use without matching application traffic, request queue growth, and repeated health-check failures.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.