Just in:
Wikimedia identifies unauthorised OpenAI agent activity across platforms // India rebuts Musk allegations over Starlink launch delay // Ping An Digital Bank Becomes Hong Kong’s First Digital Bank to Enter High-End Wealth Management Segment // LANDMARK Launches ‘Destination CENTRAL’: A District-Wide Invitation to Explore the Dynamism, Luxury, and Soul of Central // ONYX Hospitality Group Marks 60 Years with Curated Partnerships Bringing “More of What You Love” to Life // Dubai introduces colour-coded addressing across 186 neighbourhoods // Global condemnation widens over deadly Saudi airport strikes // React flaw exposes Next.js servers to service disruption // Lufthansa and three airlines halt Riyadh flight operations // First Week Of Anti-CEC Agitation Turns Into Electoral Rights Movement // UK and allies expose Integrity Tech cyber operations // Trump-Newsom Clash Assumes Special Significance Before Nov 3 Polls // Lee Kum Kee Gluten Free Soy Sauce Wins Healthy Food Guide 2026 Award // Oriental Residence Bangkok Awarded One MICHELIN Key for the Third Consecutive Year // Abu Dhabi launches AI training to accelerate government transformation // OPPO Find X10 Pro Max to Debut Globally with MediaTek’s 2nm Flagship Dimensity 9600 Pro // Almarai earmarks $4 billion for expansion through 2031 // TATA Sons’ Listing is a Boon for Its 1.77 Crore Shareholders // OpenAI extends GPT-6 access with interactive ChatGPT interface // Dubai property sales slump as war pressures prices //

React flaw exposes Next.js servers to service disruption

A high-severity vulnerability in React Server Components can allow unauthenticated attackers to overwhelm vulnerable Next. js servers through specially crafted HTTP requests, potentially making affected applications unavailable.

The flaw, identified as CVE-2026-23870 and tracked under security advisory GHSA-rv78-f8rc-xrxh, affects specific releases of React 19. Security maintainers have issued patches and urged developers operating affected server-side applications to upgrade immediately.

The vulnerability carries a severity score of 7.5 under the Common Vulnerability Scoring System. Its exploitation requires neither authentication nor user interaction, making publicly accessible server function endpoints potential targets for denial-of-service attacks.

React’s security advisory explains that malicious requests can trigger excessive processor consumption or memory exhaustion during server-side processing. These conditions may prevent applications from responding normally, disrupt legitimate traffic or cause failures in vulnerable environments.

Next. js applications using the App Router are particularly relevant because the framework incorporates React Server Components to execute portions of application logic on servers. The affected functionality processes structured requests associated with server functions, creating an attack surface when malicious input reaches vulnerable code.

The corresponding Next. js advisory, GHSA-8h8q-6873-q5fj, confirms that specially constructed requests can exploit deserialisation behaviour at App Router server function endpoints. Processing such requests may consume excessive computing resources and produce denial-of-service conditions.

Although an attack may be initiated through a single crafted request, the resulting disruption depends on the affected software version, application configuration and available computing resources. The advisories do not establish that every vulnerable deployment will freeze after one request.

Three React Server Components packages are affected: react-server-dom-webpack, react-server-dom-parcel and react-server-dom-turbopack. Vulnerable releases include versions 19.0.0 through 19.0.5, 19.1.0 through 19.1.6 and 19.2.0 through 19.2.5.

The React maintainers addressed the weakness through patched versions 19.0.6, 19.1.7 and 19.2.6. Developers using these packages have been instructed to install the corresponding corrected releases rather than rely exclusively on network-level protections.

Vercel, which maintains Next. js, incorporated the upstream correction into a coordinated security update covering multiple vulnerabilities. Its May security release addressed 13 advisories involving denial of service, authorisation bypass, server-side request forgery, cache poisoning and cross-site scripting.

The company subsequently identified Next. js versions 15.5.18 and 16.2.6 as recommended patched releases. Applications running older Next. js 13 and 14 branches require migration to a supported, corrected version.

Vercel stated that patching remains the only complete mitigation for the vulnerabilities covered by its coordinated release. It also cautioned that web application firewall rules cannot reliably block every exploitation technique associated with the disclosed issues.

Cloudflare separately confirmed that existing firewall protections developed for earlier React Server Components vulnerabilities provided coverage against the newly disclosed denial-of-service weakness. Nevertheless, it recommended updating affected application dependencies, recognising that perimeter protections do not replace software corrections.

The vulnerability is classified under uncontrolled resource consumption and allocation of resources without adequate limits. Both weaknesses concern situations where software permits operations to consume computing capacity beyond intended boundaries.

Its severity assessment identifies network accessibility, low attack complexity and the absence of authentication requirements. The recorded impact concerns availability rather than demonstrated compromise of confidentiality or integrity.

Consequently, the advisory does not establish that exploiting CVE-2026-23870 enables attackers to steal information, modify application data or execute arbitrary commands. Those consequences would require separate vulnerabilities or additional evidence.

The exposure is also narrower than the entire React ecosystem. Applications running React exclusively within browsers, without server-side React functionality, are not affected by this particular vulnerability.

Similarly, projects that do not employ frameworks, bundlers or plugins supporting React Server Components fall outside the affected configurations described by the maintainers.

For organisations maintaining production services, identifying exposure requires examining deployed framework versions and dependency packages rather than checking the headline React version alone. Applications may incorporate vulnerable server components indirectly through their frameworks.

Deployment providers have also highlighted the importance of examining publicly accessible preview environments and branch deployments, which may retain outdated application dependencies even after primary production systems have been upgraded.

The vulnerability was originally disclosed through coordinated advisories published on 6 May 2026, with subsequent security database updates documenting affected releases and corrections.

Its published severity assessment assigns high impact to service availability while recording no direct impact on information confidentiality or integrity, distinguishing this resource-exhaustion weakness from vulnerabilities permitting unauthorised access to application data.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
OPPO Find X10 Pro Max to Debut Globally with MediaTek’s 2nm Flagship Dimensity 9600 Pro // OPPO Find X10 Series to Launch Globally on October 21 with Next-Generation True-to-Life Imaging // Saudi airport strikes leave three dead, 36 injured // TATA Sons’ Listing is a Boon for Its 1.77 Crore Shareholders // Prudential Singapore launches multi-generational protection plan to help caregivers manage families’ healthcare needs // ONYX Hospitality Group Marks 60 Years with Curated Partnerships Bringing “More of What You Love” to Life // OpenAI extends GPT-6 access with interactive ChatGPT interface // BINGXUE Opens First U.S. Store in Davis, California: Shandong’s First Mass-Market Tea Beverage Brand Enters North America // Abu Dhabi launches AI training to accelerate government transformation // UK and allies expose Integrity Tech cyber operations // Dubai introduces colour-coded addressing across 186 neighbourhoods // India rebuts Musk allegations over Starlink launch delay // India establishes 5.56 km open-air quantum security link // Mubadala secures US clearance for Clear Channel takeover // Trump-Newsom Clash Assumes Special Significance Before Nov 3 Polls // Global condemnation widens over deadly Saudi airport strikes // Lufthansa and three airlines halt Riyadh flight operations // Oriental Residence Bangkok Awarded One MICHELIN Key for the Third Consecutive Year // Malicious GitHub workflows expose credentials across hundreds of repositories // Wikimedia identifies unauthorised OpenAI agent activity across platforms //