logo

CVE-2026-23870: Imperva Customers Protected Against Critical React Server Components DoS Vulnerability

ID: a66b4070-7402-565c-becd-96c88be7e7c9

STIX ID: report--a66b4070-7402-565c-becd-96c88be7e7c9

Feed Name: Security Boulevard

Threat Score
70/100

Date Published: 2026-05-09

Date Updated: 2026-05-11

Author: Gabi Sharadin

...
...

CVE-2026-23870 is a high-severity denial-of-service vulnerability in React Server Components (react-server-dom-*) and downstream frameworks like Next.js that lets unauthenticated attackers send crafted HTTP payloads which trigger recursive deserialization and sustained CPU exhaustion; affected versions span multiple major releases, patches are available, and Imperva reports protections in their Cloud and On‑Prem WAF products.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.