logo

Is Your React App Vulnerable to the CVE-2026-23870 DoS Attack?

ID: 64b2040a-962c-598e-922c-fdfd2cd00fcc

STIX ID: report--64b2040a-962c-598e-922c-fdfd2cd00fcc

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-05-08

Date Updated: 2026-05-08

Author: Ddos

...
...

**Executive Summary:** A high-severity Denial of Service vulnerability (CVE-2026-23870, CVSS 7.5) has been disclosed in React Server Components (react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack) affecting versions 19.0.0–19.0.5, 19.1.0–19.1.6, and 19.2.0–19.2.5; specially crafted HTTP requests against server function endpoints may exhaust CPU and memory, crashing or rendering servers unresponsive, and maintainers have released backported fixes (19.0.6, 19.1.7, 19.2.6) — upgrade server-side RSC dependencies immediately if applicable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.