New React Server Components Flaw Could Let Attackers Trigger DoS
ID: 0a655f58-ec4d-53ed-a8d0-0d8df41e86af
STIX ID: report--0a655f58-ec4d-53ed-a8d0-0d8df41e86af
Feed Name: GBHackers
Threat Score
A high-severity DoS vulnerability (CVE-2026-23869) in React Server Components' server-side DOM packages (react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack) across multiple 19.x release lines allows unauthenticated, low-complexity HTTP requests to trigger excessive CPU consumption and application downtime; administrators should upgrade to patched versions 19.0.5, 19.1.6, or 19.2.5.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
