logo

Incomplete Fix: High-Severity React Server Components DoS Flaw (CVE-2026-23864)

ID: 09344958-d27e-5c2d-a9fe-259f9a66b6f5

STIX ID: report--09344958-d27e-5c2d-a9fe-259f9a66b6f5

Feed Name: securityonline.info

Threat Score
60/100

Date Published: 2026-01-27

Date Updated: 2026-04-23

Author: Ddos

...
...

React maintainers disclosed CVE-2026-23864, a high-severity Denial of Service vulnerability in React Server Components (server-dom packages) that can be triggered by specially crafted HTTP requests to Server Function endpoints, potentially causing crashes, out-of-memory errors, or excessive CPU use; affected 19.0.0–19.2.3 packages have patched updates (19.0.4, 19.1.5, 19.2.4) and users are urged to upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.