CVE-2026-23864 Vulnerability Summary
Key point
A DoS vulnerability has been discovered in React Server Components that causes server crashes and CPU overload, prompting recommendations for immediate updates.
Details
Multiple high-risk security vulnerabilities have been discovered in React Server Components. While these vulnerabilities do not allow remote code execution (RCE), they can be exploited for denial-of-service (DoS) attacks.
If an attacker sends a specially crafted HTTP request to a Server Function endpoint, depending on the application configuration and code path, it can cause server crashes, out-of-memory (OOM) conditions, or excessive CPU usage.
The vulnerable packages are as follows:
react-server-dom-parcelreact-server-dom-webpackreact-server-dom-turbopack
These packages are included in frameworks and bundlers that include or depend on React Server Components implementations, such as Next.js (13.x, 14.x, 15.x, 16.x), as well as Vite, Parcel, React Router, RedwoodSDK, and Waku.
Vercel has deployed automatic protection rules via its WAF (Web Application Firewall), but since WAF alone cannot guarantee complete protection, it recommends immediately upgrading to the patched versions.
Key patched versions:
- React: 19.0.4, 19.1.5, 19.2.4
- Next.js: 15.0.8, 15.1.12, 15.2.9, 15.3.9, 15.4.11, 15.5.10, 15.6.0-canary.61, 16.0.11, 16.1.5, 16.2.0-canary.9
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.