React Server Components CVE-2026-23870 (CVSS 7.5): one crafted Server Action POST can freeze Node.js servers, including Next.js; public write-up now out; patch React 19.0.6/19.1.7/19.2.6, Next.js 15.5.16/16.2.5
CVE-2026-23870 (GitHub advisory GHSA-rv78-f8rc-xrxh, published 11 May 2026) is a high-severity denial-of-service flaw in React Server Components (react-server-dom-webpack, -turbopack and -parcel) used by React 19.x apps, including Next.js deployments that use Server Actions. When React rebuilds submitted form data before a Server Action runs, each $K (nested form) reference triggers a full scan of every field in the request, and neither the reference count nor the field count is limited. A request with 10,000 references and 10,000 fields means about 100 million string checks, run synchronously on Node.js's single event-loop thread, so other visitors see timeouts or 503s; no authentication is needed. Researcher Simon Koeck published a technical write-up on 8 October 2026 showing a request of roughly 900 KB is enough, which makes the bug easy to reproduce for anyone still unpatched. Fixed React package versions: 19.0.6, 19.1.7 and 19.2.6; Next.js fixed it in 15.5.16 and 16.2.5 (GHSA-8h8q-6873-q5fj), and the Vite React plugin has its own advisory. No in-the-wild exploitation has been reported. Primary: GitHub advisory (React); wire: Cyber Security News.
- Product
- React Server Components (react-server-dom-webpack / -turbopack / -parcel); Next.js with Server Actions
- Versions
- react-server-dom-* 19.0.0–19.0.5, 19.1.0–19.1.6, 19.2.0–19.2.5; Next.js 13.0.0 to before 15.5.16, 16.0.0 to before 16.2.5
- CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H- Exploited in Australia?
- unknown
- Patch to
- Upgrade react-server-dom-* to 19.0.6, 19.1.7 or 19.2.6 and Next.js to 15.5.16 or 16.2.5 (or later). Until then, cap request body size and rate-limit Server Action endpoints at the proxy or WAF.
Primary: React (GitHub) — GHSA-rv78-f8rc-xrxh: Denial of Service in React Server Components (11 May 2026) · Vendor: Vercel Next.js — GHSA-8h8q-6873-q5fj: Denial of Service with Server Components · CVE: CVE-2026-23870 · Cyber Security News — React Server Components flaw lets attackers freeze Next.js servers (9 Oct 2026); write-up: simonkoeck.com (8 Oct 2026)
