Is Your React App Vulnerable to the CVE-2026-23870 DoS Attack?
ID: 64b2040a-962c-598e-922c-fdfd2cd00fcc
STIX ID: report--64b2040a-962c-598e-922c-fdfd2cd00fcc
Feed Name: securityonline.info
**Executive Summary:** A high-severity Denial of Service vulnerability (CVE-2026-23870, CVSS 7.5) has been disclosed in React Server Components (react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack) affecting versions 19.0.0–19.0.5, 19.1.0–19.1.6, and 19.2.0–19.2.5; specially crafted HTTP requests against server function endpoints may exhaust CPU and memory, crashing or rendering servers unresponsive, and maintainers have released backported fixes (19.0.6, 19.1.7, 19.2.6) — upgrade server-side RSC dependencies immediately if applicable.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
