CVE-2026-23870
Published May 6, 2026
Last updated 8 days ago
AI description
CVE-2026-23870 is a denial-of-service vulnerability impacting React Server Components (RSC) and frameworks that utilize RSC functionality, such as Next.js. This flaw allows an attacker to trigger a denial of service by sending specially crafted HTTP requests to server function endpoints. Successful exploitation of this vulnerability can lead to server crashes, out-of-memory exceptions, or excessive CPU usage. The affected packages include `react-server-dom-webpack`, `react-server-dom-parcel`, and `react-server-dom-turbopack` across various versions of React 19.x.
- Description
- A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.5, 19.1.0 through 19.1.6, and 19.2.0 through 19.2.5).
- Source
- cve-assign@fb.com
- NVD status
- Analyzed
- Products
- react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- HIGH
- nvd@nist.gov
- CWE-400
- Hype score
- Not currently trending
The Recursive Trap: CVE-2026-23870 Turns React Server Components Into a DoS Weapon. The Recursive Trap: How CVE-2026-23870 Weaponizes React Server Components
@lyrie_ai
18 Jun 2026
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
直近のNext.jsのリリースで対応された脆弱性は記事を見るにこのあたりのことかな👀 CVE-2026-44574 CVE-2026-44575 CVE-2026-23870 CVE-2026-44578 CVE-2026-44579 Multiple Critical Vulnerabilities Patched in Next.js and React Server Components https://
@oTheRwoRldy
14 May 2026
301 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Next.js v16.2.4 Security PoC Collection CVE-2026-23870 CVE-2026-44575 CVE-2026-44579 CVE-2026-44574 CVE-2026-44578 CVE-2026-44573 CVE-2026-44581 CVE-2026-44580 CVE-2026-44577 CVE-2026-44576 CVE-2026-44582 CVE-2026-44572 https://t.co/255KwkLd0c via: Pr0xy
@Psycho10k_
11 May 2026
1975 Impressions
8 Retweets
43 Likes
28 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:facebook:react-server-dom-parcel:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "A1678B87-ED02-4BF8-A08C-A87759FDFAEC",
"versionEndIncluding": "19.0.5",
"versionStartIncluding": "19.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:facebook:react-server-dom-parcel:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "D6962C45-D7EC-4DF0-B9C6-DB96A84384FA",
"versionEndIncluding": "19.1.6",
"versionStartIncluding": "19.1.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:facebook:react-server-dom-parcel:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "640841EA-DA32-4459-9F6A-FCAC50E3D446",
"versionEndIncluding": "19.2.5",
"versionStartIncluding": "19.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:facebook:react-server-dom-turbopack:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "B1F8B3DF-589C-4CEC-9BD6-854B23406AF0",
"versionEndIncluding": "19.0.5",
"versionStartIncluding": "19.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:facebook:react-server-dom-turbopack:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "532D814C-29FF-400A-971F-49C16C6AA131",
"versionEndIncluding": "19.1.6",
"versionStartIncluding": "19.1.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:facebook:react-server-dom-turbopack:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "385AECA1-DEF6-4349-9BFD-807B071740F1",
"versionEndIncluding": "19.2.5",
"versionStartIncluding": "19.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:facebook:react-server-dom-webpack:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "AA8882E3-789E-4A7B-B47E-6286F60F719E",
"versionEndIncluding": "19.0.5",
"versionStartIncluding": "19.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:facebook:react-server-dom-webpack:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "BB14FFF9-8903-4AAC-A563-B498394C75C0",
"versionEndIncluding": "19.1.6",
"versionStartIncluding": "19.1.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:facebook:react-server-dom-webpack:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "7A563960-4696-481F-8BAB-5A437AB5F14A",
"versionEndIncluding": "19.2.5",
"versionStartIncluding": "19.2.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]