VYPR
patchPublished Oct 9, 2026· 1 source

React Server Components Vulnerability Allows Denial-of-Service Attacks on Next.js Servers

A critical denial-of-service vulnerability (CVE-2026-23870) in React Server Components can freeze Next.js servers with a single crafted POST request.

A high-severity denial-of-service vulnerability, tracked as CVE-2026-23870, has been discovered in React Server Components, posing a significant risk to applications built with React 19.x and Next.js. The flaw allows remote attackers to freeze vulnerable servers by sending a single, specially crafted POST request to a Server Function endpoint. This vulnerability, with a CVSS score of 7.5, affects the core functionality of React Server Components packages used in many modern Next.js deployments that leverage Server Actions.

The root cause of the vulnerability lies in an inefficient process within React for rebuilding submitted form data before a Server Action is executed. Attackers do not need to breach application security or access sensitive data; instead, they can exploit this inefficiency by forcing the server to perform an excessive number of repeated checks. This consumes critical CPU resources, rendering the server unresponsive to legitimate users and effectively freezing its operations.

Modern React applications frequently utilize Server Actions, which enable direct invocation of backend functions from form submissions. This feature requires React to parse incoming HTTP requests and reconstruct the submitted form fields prior to the action's execution. The vulnerability specifically targets a reference type, denoted as $K, within React's form-data format. This reference signals that a nested form structure needs to be rebuilt. The problematic logic dictates that for each $K reference, React must create a comprehensive list of all fields within the submitted request and then meticulously scan this entire list for matching entries.

This rebuilding process becomes computationally expensive when a request contains a large number of $K references alongside a substantial quantity of ordinary form fields. Each $K reference triggers another full scan of the submitted field list. For instance, a POST request with 10,000 references and 10,000 form fields could potentially lead to approximately 100 million string comparisons. A proof-of-concept demonstrated that a request of around 900 KB could initiate this resource-intensive workload, highlighting that the issue is not the request size itself but the repeated processing of the data structure.

Many Next.js deployments operate on Node.js, an environment where CPU-intensive synchronous processing can easily block the event loop. While React is engaged in scanning the attacker-controlled form fields, the server's ability to process other incoming requests is severely hampered. Consequently, legitimate users may encounter prolonged page load times, request timeouts, or HTTP 503 Service Unavailable errors. A sustained barrage of malicious POST requests could render an application instance unavailable long enough for automated health checks or load balancers to flag it as unhealthy and remove it from active service.

The vulnerability is particularly concerning because the resource-intensive parsing occurs before any application-level Server Action logic is invoked. This means that security protections implemented within the Server Action itself are ineffective against this particular attack vector. While publicly accessible Server Actions are the most exposed, authenticated applications are also at risk if any normal user can reach the vulnerable endpoint.

React has addressed the flaw in versions 19.0.6, 19.1.7, and 19.2.6. The vulnerable version ranges include React 19.0.0 through 19.0.5, 19.1.0 through 19.1.6, and 19.2.0 through 19.2.5. Organizations running older releases are strongly advised to upgrade immediately. Next.js users should carefully verify their resolved dependency tree, as affected React server-dom packages might be included through framework dependencies, especially in applications using the App Router, React Server Components, or Server Actions.

The fix implemented by React modifies the form-data processing path to scan and consume fields only once, eliminating the repeated work that led to CPU exhaustion. Beyond patching, administrators should review edge and reverse-proxy configurations, including POST body size limits and request rate controls, to further mitigate exposure. Continuous monitoring for unusual POST activity, high CPU usage, and repeated health check failures against Server Action endpoints is also recommended.

Synthesized by Vypr AI