Denial of Service Alert: React Server Components Vulnerability Causes CPU Spikes
ID: 2ef26202-9761-572f-9da5-2e8684644bcc
STIX ID: report--2ef26202-9761-572f-9da5-2e8684644bcc
Feed Name: securityonline.info
Threat Score
React warns of CVE-2026-23869, a denial-of-service flaw in React Server Components (affecting react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack) in versions 19.0.0–19.0.4, 19.1.0–19.1.5, and 19.2.0–19.2.4; specially crafted HTTP requests to Server Function endpoints can cause excessive CPU usage for up to a minute and potentially take down servers. Developers are urged to patch immediately to 19.0.5, 19.1.6, or 19.2.5 to mitigate the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
