The flaw, identified as CVE-2026-23870 and tracked under security advisory GHSA-rv78-f8rc-xrxh, affects specific releases of React 19. Security maintainers have issued patches and urged developers operating affected server-side applications to upgrade immediately.
The vulnerability carries a severity score of 7.5 under the Common Vulnerability Scoring System. Its exploitation requires neither authentication nor user interaction, making publicly accessible server function endpoints potential targets for denial-of-service attacks.
React’s security advisory explains that malicious requests can trigger excessive processor consumption or memory exhaustion during server-side processing. These conditions may prevent applications from responding normally, disrupt legitimate traffic or cause failures in vulnerable environments.
Next. js applications using the App Router are particularly relevant because the framework incorporates React Server Components to execute portions of application logic on servers. The affected functionality processes structured requests associated with server functions, creating an attack surface when malicious input reaches vulnerable code.
The corresponding Next. js advisory, GHSA-8h8q-6873-q5fj, confirms that specially constructed requests can exploit deserialisation behaviour at App Router server function endpoints. Processing such requests may consume excessive computing resources and produce denial-of-service conditions.
Although an attack may be initiated through a single crafted request, the resulting disruption depends on the affected software version, application configuration and available computing resources. The advisories do not establish that every vulnerable deployment will freeze after one request.
Three React Server Components packages are affected: react-server-dom-webpack, react-server-dom-parcel and react-server-dom-turbopack. Vulnerable releases include versions 19.0.0 through 19.0.5, 19.1.0 through 19.1.6 and 19.2.0 through 19.2.5.
The React maintainers addressed the weakness through patched versions 19.0.6, 19.1.7 and 19.2.6. Developers using these packages have been instructed to install the corresponding corrected releases rather than rely exclusively on network-level protections.
Vercel, which maintains Next. js, incorporated the upstream correction into a coordinated security update covering multiple vulnerabilities. Its May security release addressed 13 advisories involving denial of service, authorisation bypass, server-side request forgery, cache poisoning and cross-site scripting.
The company subsequently identified Next. js versions 15.5.18 and 16.2.6 as recommended patched releases. Applications running older Next. js 13 and 14 branches require migration to a supported, corrected version.
Vercel stated that patching remains the only complete mitigation for the vulnerabilities covered by its coordinated release. It also cautioned that web application firewall rules cannot reliably block every exploitation technique associated with the disclosed issues.
Cloudflare separately confirmed that existing firewall protections developed for earlier React Server Components vulnerabilities provided coverage against the newly disclosed denial-of-service weakness. Nevertheless, it recommended updating affected application dependencies, recognising that perimeter protections do not replace software corrections.
The vulnerability is classified under uncontrolled resource consumption and allocation of resources without adequate limits. Both weaknesses concern situations where software permits operations to consume computing capacity beyond intended boundaries.
Its severity assessment identifies network accessibility, low attack complexity and the absence of authentication requirements. The recorded impact concerns availability rather than demonstrated compromise of confidentiality or integrity.
Consequently, the advisory does not establish that exploiting CVE-2026-23870 enables attackers to steal information, modify application data or execute arbitrary commands. Those consequences would require separate vulnerabilities or additional evidence.
The exposure is also narrower than the entire React ecosystem. Applications running React exclusively within browsers, without server-side React functionality, are not affected by this particular vulnerability.
Similarly, projects that do not employ frameworks, bundlers or plugins supporting React Server Components fall outside the affected configurations described by the maintainers.
For organisations maintaining production services, identifying exposure requires examining deployed framework versions and dependency packages rather than checking the headline React version alone. Applications may incorporate vulnerable server components indirectly through their frameworks.
Deployment providers have also highlighted the importance of examining publicly accessible preview environments and branch deployments, which may retain outdated application dependencies even after primary production systems have been upgraded.
The vulnerability was originally disclosed through coordinated advisories published on 6 May 2026, with subsequent security database updates documenting affected releases and corrections.
Its published severity assessment assigns high impact to service availability while recording no direct impact on information confidentiality or integrity, distinguishing this resource-exhaustion weakness from vulnerabilities permitting unauthorised access to application data.
Follow Arabian Post
Select Arabian Post as your preferred source on Google and MSN News for trusted business news and Arab politics and updates.