logo

React2DoS (CVE-2026-23869): When the Flight Protocol Crashes at Takeoff

ID: 4a2b810a-f222-506b-b80d-c17edce7bf45

STIX ID: report--4a2b810a-f222-506b-b80d-c17edce7bf45

Feed Name: Security Boulevard

Threat Score
70/100

Date Published: 2026-04-09

Date Updated: 2026-04-22

Author: Yohann Sillam

...
...

This report discloses "React2DoS" (CVE-2026-23869), an unauthenticated remote denial-of-service in React Server Components' Flight protocol where crafted payloads with recursive Map/Set references cause quadratic deserialization work, allowing small requests to exhaust server CPU for minutes; the issue affects React RSC ≤ 19.2.4 and was fixed in 19.2.5.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.