Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Warden Stealer Spreads Via Malvertising and Cracked Software
October 9, 2026
MATCHBOIL Malware Uses Cloudflare to Hide C2 Servers, Delivers Backdoor Payloads
October 9, 2026
Telegram Desktop Critical Flaw Lets Attackers Take Over Accounts
October 9, 2026
Home/CyberSecurity News/Critical React Server Components Flaw Freezes Next.js Servers
CyberSecurity News

Critical React Server Components Flaw Freezes Next.js Servers

Key Takeaways A high-severity denial-of-service vulnerability (CVE-2026-23870) has been identified in React Server Components. This flaw allows remote attackers to freeze Next.js servers by sending...

Jennifer sherman
Jennifer sherman
October 9, 2026 4 Min Read
8 0

Key Takeaways

  • A high-severity denial-of-service vulnerability (CVE-2026-23870) has been identified in React Server Components.
  • This flaw allows remote attackers to freeze Next.js servers by sending specially crafted POST requests.
  • The issue, rated 7.5 CVSS, affects React 19.x applications, including many Next.js deployments utilizing Server Actions.
  • Patches are available in React versions 19.0.6, 19.1.7, and 19.2.6.

Critical Flaw in React Server Components Threatens Next.js Stability

A significant denial-of-service (DoS) vulnerability, tracked as CVE-2026-23870, has emerged within React Server Components, posing a serious threat to Next.js deployments. This high-severity flaw enables a remote attacker to render vulnerable Next.js servers unresponsive through the transmission of specifically crafted POST requests to Server Function endpoints.

Table Of Content

  • Key Takeaways
  • Critical Flaw in React Server Components Threatens Next.js Stability
  • Root Cause: Inefficient Form Data Processing
  • Exploitation and Impact
  • The Fix
  • What You Should Do

The vulnerability carries a CVSS score of 7.5, underscoring its potential impact. It specifically targets React Server Components packages integral to React 19.x applications, encompassing a broad spectrum of Next.js instances that leverage Server Actions for backend interactions.

Root Cause: Inefficient Form Data Processing

The underlying problem stems from how React reconstructs submitted form data prior to the execution of a Server Action. An attacker does not need to compromise the application’s security or gain unauthorized access to sensitive information. Instead, the exploit forces the server into a state of excessive resource consumption, repeatedly performing computationally intensive checks, thereby depleting CPU cycles and preventing it from responding to legitimate user requests.

Modern React applications frequently employ Server Actions to facilitate direct calls to backend functions via form submissions. This mechanism necessitates React to parse incoming HTTP requests and meticulously reassemble submitted form fields before any backend logic can execute. The vulnerability resides within this parsing process.

Specifically, the problematic code handles unique references embedded within React’s form-data format. One particular reference type, denoted by “$K,” instructs React to reconstruct a nested form structure. To resolve each “$K” reference, React’s previous implementation generated a comprehensive list of every field in the submitted request, subsequently scanning this entire list for corresponding entries.

This approach becomes extremely resource-intensive when a request contains a large number of both “$K” references and standard form fields. Each “$K” reference triggers an additional full scan of the submitted field list. For instance, a POST request with 10,000 references and 10,000 form fields could lead to approximately 100 million string comparisons, overwhelming the server’s processing capabilities.

Exploitation and Impact

As researcher Simon Koeck showed in a proof-of-concept, a POST request of approximately 900 KB can initiate this burdensome workload. The core issue is not merely the size of the request itself, but the repeated and inefficient processing React performs when handling the submitted data structure.

Given that many Next.js deployments operate on Node.js, CPU-intensive synchronous processing can effectively block the event loop. While React is engrossed in scanning the attacker-controlled form fields, the server becomes incapable of processing other incoming requests in a timely manner. This can lead to legitimate users experiencing delayed page loads, request timeouts, or HTTP 503 errors. Persistent malicious POST requests could keep an application instance unavailable long enough for automated health checks or load balancers to flag it as unhealthy and remove it from service entirely.

The severity of this vulnerability is amplified by the fact that the costly parsing occurs before any application-specific Server Action logic can execute. This means that protective measures implemented within the Server Action itself are ineffective in preventing the initial, resource-draining request parsing. While publicly accessible Server Actions are most exposed, authenticated applications are also at risk if any standard user can reach the vulnerable endpoint.

React’s official advisory confirms that specially crafted HTTP requests targeting server function endpoints can result in excessive CPU utilization, out-of-memory conditions, or outright server crashes. The National Institute of Standards and Technology (NIST) has categorized this issue as CWE-400, or uncontrolled resource consumption.

The CVE-2026-23870 vulnerability impacts the following React Server Components packages: react-server-dom-webpack, react-server-dom-turbopack, and react-server-dom-parcel. Affected versions include React 19.0.0 through 19.0.5, 19.1.0 through 19.1.6, and 19.2.0 through 19.2.5. The patched releases are 19.0.6, 19.1.7, and 19.2.6.

Next.js users must inspect their resolved dependency tree, rather than relying solely on their top-level Next.js version. Applications leveraging the App Router, React Server Components, or Server Actions may inadvertently include one of the vulnerable React server-dom packages through their framework dependencies.

The Fix

React has addressed the vulnerability by modifying the form-data processing path. The updated logic ensures that fields are now scanned only once and consumed as they are handled, eliminating the need to rescan the complete list for every nested reference. This critical change removes the repeated-work condition that led to the CPU exhaustion issue.

What You Should Do

  • Update React: Immediately upgrade React and the relevant React Server Components packages to the fixed versions (19.0.6, 19.1.7, or 19.2.6) in your supported branch.
  • Rebuild and Redeploy: After updating, rebuild all application artifacts and redeploy all affected environments.
  • Review Dependency Tree: For Next.js users, verify your resolved dependency tree to ensure all React server-dom packages are updated, even if your top-level Next.js version appears current.
  • Enhance Edge Controls: Review and strengthen edge and reverse-proxy controls, including POST body-size limits, request-rate controls, and timeouts. While these measures can reduce exposure, patching React remains the primary and most effective fix.
  • Monitor for Anomalies: Administrators should actively monitor for unusual POST activity targeting pages that expose Server Actions. Look for bursts of multipart form-data requests, unexplained high CPU usage, growth in request queues, and repeated health-check failures.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEPatchSecurityVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

FBI Seized China-Linked Hacking Tools to Scan for Vulnerabilities and Spear Phish

Next Post

Malicious PDF Reader on Google Play Delivers Anatsa Banking Trojan

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Top 10 Bug Bounty Platforms of 2026 Ranked and Scored
October 9, 2026
Anthropic’s New OSS Scanner Identifies Open-Source Vulnerabilities
October 9, 2026
Top 10 IaC Security Tools for 2026
October 9, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us