React2DoS (CVE-2026-23869): When the Flight Protocol Crashes at Takeoff
ID: 4a2b810a-f222-506b-b80d-c17edce7bf45
STIX ID: report--4a2b810a-f222-506b-b80d-c17edce7bf45
Feed Name: Security Boulevard
Threat Score
This report discloses "React2DoS" (CVE-2026-23869), an unauthenticated remote denial-of-service in React Server Components' Flight protocol where crafted payloads with recursive Map/Set references cause quadratic deserialization work, allowing small requests to exhaust server CPU for minutes; the issue affects React RSC ≤ 19.2.4 and was fixed in 19.2.5.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
