logo

React Server Components Vulnerability Enables DoS Attacks

ID: c4a3dd6e-5cae-5f76-bbc2-a69e80a7c423

STIX ID: report--c4a3dd6e-5cae-5f76-bbc2-a69e80a7c423

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-04-10

Date Updated: 2026-05-05

Author: Abinaya

...
...

A high-severity vulnerability (CVE-2026-23869) in React Server Components allows unauthenticated attackers to trigger prolonged CPU exhaustion and Denial of Service via specially crafted HTTP requests to Server Function endpoints. Affected packages include react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack across 19.0–19.2 branches; fixed versions are 19.0.5, 19.1.6, and 19.2.5—development teams should audit dependencies and upgrade immediately if using server components.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.