CVE-2026-23870

Published May 6, 2026

Last updated 7 days ago

CVSS high 7.5
Server
React-Server-Dom-Webpack
React-Server-Dom-Parcel
React-Server-Dom-Turbopack

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-23870 is a denial-of-service vulnerability impacting React Server Components (RSC) and frameworks that utilize RSC functionality, such as Next.js. This flaw allows an attacker to trigger a denial of service by sending specially crafted HTTP requests to server function endpoints. Successful exploitation of this vulnerability can lead to server crashes, out-of-memory exceptions, or excessive CPU usage. The affected packages include `react-server-dom-webpack`, `react-server-dom-parcel`, and `react-server-dom-turbopack` across various versions of React 19.x.

Description
A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.5, 19.1.0 through 19.1.6, and 19.2.0 through 19.2.5).
Source
cve-assign@fb.com
NVD status
Received

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity
HIGH

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

4

References

Sources include official advisories and independent security research.