
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23864 describes multiple Denial of Service (DoS) vulnerabilities in React Server Components, specifically affecting the npm packages react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerabilities were disclosed on January 26, 2026, and notably represent an incomplete fix for prior DoS issues in the same components. Affected versions span React 19.0.0–19.0.3, 19.1.0–19.1.4, and 19.2.0–19.2.3 across all three packages. The CVSS v3.1 base score is 7.5 (High) (GitHub Advisory, Meta Advisory).
The root cause is classified as CWE-400 (Uncontrolled Resource Consumption) and CWE-502 (Deserialization of Untrusted Data), indicating that the Server Components' handling of incoming data fails to adequately constrain resource usage during deserialization or processing (GitHub Advisory, Feedly). Attackers exploit this by sending specially crafted HTTP requests to Server Function endpoints, which can trigger server crashes, out-of-memory (OOM) exceptions, or excessive CPU consumption depending on the specific code path, application configuration, and application code. No authentication or user interaction is required, and the attack is network-accessible with low complexity. The advisory explicitly notes that prior patches were incomplete, meaning multiple distinct vulnerable code paths remained after the initial fix (GitHub Advisory). Applications not using React Server Components (RSC) or not using a framework/bundler that supports RSC are not affected.
Successful exploitation results in a high availability impact — attackers can crash the server process, exhaust memory, or cause excessive CPU usage, rendering the application unavailable to legitimate users (GitHub Advisory, Meta Advisory). There is no confidentiality or integrity impact associated with this vulnerability. The scope is limited to the affected server component, but a sustained attack could cause prolonged service outages for any application built on Next.js or other frameworks leveraging React Server Components with the affected packages.
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 1.98% (84th percentile), indicating a moderate-to-elevated probability of exploitation relative to other CVEs (GitHub Advisory). The vulnerability is unauthenticated and network-accessible with low attack complexity, making it attractive for opportunistic attackers targeting publicly exposed Next.js or RSC-based applications. No threat actor attribution or CISA KEV catalog listing has been reported. Cloudflare WAF and Citrix NetScaler WAF have released signatures to detect exploitation attempts (Cloudflare Changelog, Citrix Community).
JavaScript heap out of memory) or unhandled exceptions during request processing.The React team has released patched versions backported across all affected minor branches: 19.0.4, 19.1.5, and 19.2.4 for all three affected packages (react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack). Upgrading to the latest patched version is the strongly recommended remediation (GitHub Advisory, Meta Advisory). Applications that do not use React Server Components or do not use a framework/bundler supporting RSC are not affected and do not require action. As a temporary network-layer mitigation, deploying WAF rules (Cloudflare and Citrix NetScaler WAF have released signatures) can help block exploitation attempts while patching is underway (Cloudflare Changelog).
The disclosure generated significant community attention, with hosting platforms Vercel and Netlify publishing their own changelogs and summaries of the vulnerability shortly after disclosure (Vercel Changelog, Netlify Changelog). Akamai published a dedicated security research blog post analyzing the vulnerability (Akamai Blog). Security researchers including jviide and mufeedvh were credited as reporters in the GitHub Advisory, and jviide discussed the issue on Mastodon and Bluesky. The Hacker News community discussed the vulnerability, and it was featured in multiple weekly security recaps including The Hacker News and This Week in React newsletters. Security Online Info noted that this CVE represents an incomplete fix for prior DoS issues, adding urgency to the patching recommendation (Security Online).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."