CVE-2026-23869 – Denial of Service in React Server Components (react-server-dom-*)
A high-severity denial of service vulnerability, CVE-2026-23869 (CVSS 7.5), affects React Server Components implementations in the react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack packages. The issue impacts versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4. An attacker can send specially crafted HTTP requests to App Router Server Function endpoints; when the request payload is deserialized by the server, it triggers excessive CPU usage for up to approximately one minute and ends in a thrown error that is catchable. The flaw has an availability impact (denial of service) but does not affect confidentiality or integrity, and it can be triggered remotely without authentication.
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.
References:
