Critical React Server Components Flaw Freezes Next.js Servers
Key Takeaways A high-severity denial-of-service vulnerability (CVE-2026-23870) has been identified in React Server Components. This flaw allows remote attackers to freeze Next.js servers by sending...
Key Takeaways
- A high-severity denial-of-service vulnerability (CVE-2026-23870) has been identified in React Server Components.
- This flaw allows remote attackers to freeze Next.js servers by sending specially crafted POST requests.
- The issue, rated 7.5 CVSS, affects React 19.x applications, including many Next.js deployments utilizing Server Actions.
- Patches are available in React versions 19.0.6, 19.1.7, and 19.2.6.
Critical Flaw in React Server Components Threatens Next.js Stability
A significant denial-of-service (DoS) vulnerability, tracked as CVE-2026-23870, has emerged within React Server Components, posing a serious threat to Next.js deployments. This high-severity flaw enables a remote attacker to render vulnerable Next.js servers unresponsive through the transmission of specifically crafted POST requests to Server Function endpoints.
Table Of Content
The vulnerability carries a CVSS score of 7.5, underscoring its potential impact. It specifically targets React Server Components packages integral to React 19.x applications, encompassing a broad spectrum of Next.js instances that leverage Server Actions for backend interactions.
Root Cause: Inefficient Form Data Processing
The underlying problem stems from how React reconstructs submitted form data prior to the execution of a Server Action. An attacker does not need to compromise the application’s security or gain unauthorized access to sensitive information. Instead, the exploit forces the server into a state of excessive resource consumption, repeatedly performing computationally intensive checks, thereby depleting CPU cycles and preventing it from responding to legitimate user requests.
Modern React applications frequently employ Server Actions to facilitate direct calls to backend functions via form submissions. This mechanism necessitates React to parse incoming HTTP requests and meticulously reassemble submitted form fields before any backend logic can execute. The vulnerability resides within this parsing process.
Specifically, the problematic code handles unique references embedded within React’s form-data format. One particular reference type, denoted by “$K,” instructs React to reconstruct a nested form structure. To resolve each “$K” reference, React’s previous implementation generated a comprehensive list of every field in the submitted request, subsequently scanning this entire list for corresponding entries.
This approach becomes extremely resource-intensive when a request contains a large number of both “$K” references and standard form fields. Each “$K” reference triggers an additional full scan of the submitted field list. For instance, a POST request with 10,000 references and 10,000 form fields could lead to approximately 100 million string comparisons, overwhelming the server’s processing capabilities.
Exploitation and Impact
As researcher Simon Koeck showed in a proof-of-concept, a POST request of approximately 900 KB can initiate this burdensome workload. The core issue is not merely the size of the request itself, but the repeated and inefficient processing React performs when handling the submitted data structure.
Given that many Next.js deployments operate on Node.js, CPU-intensive synchronous processing can effectively block the event loop. While React is engrossed in scanning the attacker-controlled form fields, the server becomes incapable of processing other incoming requests in a timely manner. This can lead to legitimate users experiencing delayed page loads, request timeouts, or HTTP 503 errors. Persistent malicious POST requests could keep an application instance unavailable long enough for automated health checks or load balancers to flag it as unhealthy and remove it from service entirely.
The severity of this vulnerability is amplified by the fact that the costly parsing occurs before any application-specific Server Action logic can execute. This means that protective measures implemented within the Server Action itself are ineffective in preventing the initial, resource-draining request parsing. While publicly accessible Server Actions are most exposed, authenticated applications are also at risk if any standard user can reach the vulnerable endpoint.
React’s official advisory confirms that specially crafted HTTP requests targeting server function endpoints can result in excessive CPU utilization, out-of-memory conditions, or outright server crashes. The National Institute of Standards and Technology (NIST) has categorized this issue as CWE-400, or uncontrolled resource consumption.
The CVE-2026-23870 vulnerability impacts the following React Server Components packages: react-server-dom-webpack, react-server-dom-turbopack, and react-server-dom-parcel. Affected versions include React 19.0.0 through 19.0.5, 19.1.0 through 19.1.6, and 19.2.0 through 19.2.5. The patched releases are 19.0.6, 19.1.7, and 19.2.6.
Next.js users must inspect their resolved dependency tree, rather than relying solely on their top-level Next.js version. Applications leveraging the App Router, React Server Components, or Server Actions may inadvertently include one of the vulnerable React server-dom packages through their framework dependencies.
The Fix
React has addressed the vulnerability by modifying the form-data processing path. The updated logic ensures that fields are now scanned only once and consumed as they are handled, eliminating the need to rescan the complete list for every nested reference. This critical change removes the repeated-work condition that led to the CPU exhaustion issue.
What You Should Do
- Update React: Immediately upgrade React and the relevant React Server Components packages to the fixed versions (19.0.6, 19.1.7, or 19.2.6) in your supported branch.
- Rebuild and Redeploy: After updating, rebuild all application artifacts and redeploy all affected environments.
- Review Dependency Tree: For Next.js users, verify your resolved dependency tree to ensure all React server-dom packages are updated, even if your top-level Next.js version appears current.
- Enhance Edge Controls: Review and strengthen edge and reverse-proxy controls, including POST body-size limits, request-rate controls, and timeouts. While these measures can reduce exposure, patching React remains the primary and most effective fix.
- Monitor for Anomalies: Administrators should actively monitor for unusual POST activity targeting pages that expose Server Actions. Look for bursts of multipart form-data requests, unexplained high CPU usage, growth in request queues, and repeated health-check failures.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.