Threat reportVulnerabilityTL-2026-3096
React Server Components DoS Vulnerability (CVE-2026-23870) Lets Attackers Freeze Next.js Servers With a Single POST Request
React Server Components DoS Vulnerability (CVE-2026-23870) (TL-2026-3096) is a high-severity software vulnerability scored CVSS 7.5, first published 2026-10-09. It has no confirmed attribution, affects Meta (Facebook) react-server-dom-webpack, references 1 CVE (CVE-2026-23870), maps to 8 MITRE ATT&CK techniques (T1190, T1499, T1499.003), and is covered by 9 detection rules and 12 indicators of compromise.
- CVSS
- 7.5/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 8MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 12Indicators of compromise
Key facts for TL-2026-3096
- Threat ID
- TL-2026-3096
- Severity
- HIGH
- CVSS
- 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, ecommerce, finance, news - media, saas
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 12
- Updates
- 2026-10-09 · revalidated 1× · latest source
Malware and tooling in React Server Components DoS Vulnerability (CVE-2026-23870)
Malware and tooling: Public GitHub PoC for CVE-2026-23870 (runnable scripts targeting Next.js 16.2.4)
How React Server Components DoS Vulnerability (CVE-2026-23870) works
CVE-2026-23870 is an unauthenticated denial-of-service flaw (CWE-400/CWE-770) in the React Server Components packages react-server-dom-webpack, react-server-dom-turbopack and react-server-dom-parcel. A crafted ~900 KB multipart POST to a Server Function endpoint forces quadratic form-data processing that blocks the Node.js event loop. Fixed in React 19.0.6, 19.1.7 and 19.2.6; a public PoC exists but no in-the-wild exploitation is reported.
CVE-2026-23870 affects the React Server Components (RSC) server-side packages react-server-dom-webpack, react-server-dom-turbopack and react-server-dom-parcel in React 19.0.0-19.0.5, 19.1.0-19.1.6 and 19.2.0-19.2.5. The CVE was assigned by Meta and carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The advisory (GHSA-rv78-f8rc-xrxh) lists CWE-400 and CWE-770; Red Hat classifies it as CWE-770. Applications are exposed only if they run server-side React code through a framework or bundler that supports React Server Components (for example Next.js, React Router, Waku, @parcel/rsc, @vitejs/plugin-rsc, rwsdk).
Root cause (per researcher Simon Koeck's write-up): when React rebuilds form data for a Server Action/Server Function request, it resolves each $K pointer (a reference marker for a nested form) by walking the entire list of request fields and matching names against a prefix. There was no cap on either the number of pointers or the number of fields, so the cost is quadratic. A request with 10,000 $K pointers and 10,000 filler fields forces about 100 million string comparisons.
Proof of concept: the payload uses 10,000 $K pointers nested one level deep, which avoids the argument-count limits. They sit under $ACTION_0:2 to avoid the nesting-depth restrictions, and are paired with 10,000 filler fields. The total request is about 900 KB. The attacker needs no authentication; the Server Action ID can be extracted from the target's served HTML/JavaScript. Reported impact: about 4 seconds of server freeze for a single request on a production build on a laptop, and about 10 seconds per request on production infrastructure. Three sequential requests triggered load-balancer failover. Because Node.js is single-threaded, the event loop is blocked and other requests queue or time out. Symptoms are CPU saturation, HTTP 503/timeouts and failed health checks that can remove nodes from load balancers. Advisory text also notes out-of-memory exceptions or process termination are possible.
Fix: React changed the logic to traverse the form data once per request, using a bookmark that tracks position and deletes consumed fields, which removes the quadratic behavior. Patched releases are 19.0.6, 19.1.7 and 19.2.6. Red Hat reports no practical mitigation other than upgrading. Defense-in-depth recommended by the source article: POST body-size limits, request-rate controls and timeouts, and monitoring for unusual POST activity against Server Action endpoints.
Context: this follows earlier RSC denial-of-service disclosures (December 2025 DoS and source-code exposure; CVE-2026-23864 in January 2026 for an incomplete fix; CVE-2026-23869 and CVE-2026-23870 in May 2026). Wiz reports the CVE is not in the CISA KEV catalog, with no confirmed in-the-wild exploitation, and a public PoC on GitHub targeting Next.js 16.2.4. No threat actor attribution or network IOCs are published.
MITRE ATT&CK techniques used in TL-2026-3096
Initial Access
T1190 Exploit Public-Facing Application
Impact
T1499 Endpoint Denial of Service; T1499.003 Endpoint Denial of Service: Application Exhaustion Flood; T1499.004 Endpoint Denial of Service: Application or System Exploitation
Resource Development
T1587.004 Develop Capabilities: Exploits; T1588.006 Obtain Capabilities
Reconnaissance
T1592.002 Gather Victim Host Information; T1594 Search Victim-Owned Websites
Affected products and versions in React Server Components DoS Vulnerability (CVE-2026-23870)
- Meta (Facebook) — react-server-dom-webpack
Vulnerable versions: 19.0.0-19.0.5; 19.1.0-19.1.6; 19.2.0-19.2.5
Fixed in: 19.0.6; 19.1.7; 19.2.6 - Meta (Facebook) — react-server-dom-turbopack
Vulnerable versions: 19.0.0-19.0.5; 19.1.0-19.1.6; 19.2.0-19.2.5
Fixed in: 19.0.6; 19.1.7; 19.2.6 - Meta (Facebook) — react-server-dom-parcel
Vulnerable versions: 19.0.0-19.0.5; 19.1.0-19.1.6; 19.2.0-19.2.5
Fixed in: 19.0.6; 19.1.7; 19.2.6
Remediation for React Server Components DoS Vulnerability (CVE-2026-23870)
Patches
- React 19.0.6
- React 19.1.7
- React 19.2.6
Immediate actions
- Upgrade react-server-dom-webpack, react-server-dom-turbopack and react-server-dom-parcel to 19.0.6, 19.1.7 or 19.2.6 (or the matching patched framework release)
- Enforce POST body-size limits at the reverse proxy / CDN / WAF in front of Server Action endpoints
- Apply request-rate controls and request timeouts on Server Function endpoints
Workarounds
- No vendor workaround is available (Red Hat: mitigation not available); body-size limits, rate limiting and timeouts only reduce impact
Longer-term hardening
- Monitor for unusual POST activity (large multipart bodies, many $K / $ACTION_ fields) against Server Action endpoints
- Alert on event-loop lag, sustained CPU saturation and health-check failures on Node.js SSR workloads
- Maintain an inventory of applications using React Server Components and track React security advisories
CVEs associated with React Server Components DoS Vulnerability (CVE-2026-23870)
Weaknesses (CWE) in React Server Components DoS Vulnerability (CVE-2026-23870)
Timeline of React Server Components DoS Vulnerability (CVE-2026-23870)
- Initial React Server Components DoS and source-code exposure vulnerabilities disclosed, beginning the series of RSC advisories that includes CVE-2026-23870
- CVE-2026-23864 identified as covering incomplete earlier RSC DoS fixes
- CVE-2026-23869 (related RSC DoS, fixed in React 19.0.5/19.1.6/19.2.5 and Next.js 15.5.15/16.2.3) disclosed, preceding CVE-2026-23870
- Simon Koeck reports the form-data $K pointer scanning DoS to Meta
- React releases 19.0.6, 19.1.7 and 19.2.6; GHSA-rv78-f8rc-xrxh and CVE-2026-23870 (CVSS 7.5) published in NVD
- Vercel ships the Next.js May 2026 security release (13 advisories) including the CVE-2026-23870 fix in Next.js 15.5.18 and 16.2.6; states no workarounds and no WAF rules
- Next.js advisory GHSA-8h8q-6873-q5fj for CVE-2026-23870 published to OSV (CVSS 7.5, CWE-770)
- NVD record for CVE-2026-23870 last modified
- Simon Koeck publishes the technical write-up and ~900 KB PoC (10,000 $K pointers + 10,000 filler fields)
- Cyber Security News reports the flaw can freeze Next.js servers with a single POST request; no in-the-wild exploitation reported
Update history for TL-2026-3096
- 2026-10-09 — React Server Components DoS via $K reference deserialization (CVE-2026-23870) freezes Next.js servers with a single request: What changed No severity, exploitability or status change (HIGH / POC_PUBLIC / ACTIVE stay as is). Adds Next.js remediation coverage: fixed in 15.5.18 and 16.2.6; 13.x/14.x have no fix on their lines. Vercel states there are no workarounds
Sources cited for React Server Components DoS Vulnerability (CVE-2026-23870)
- React Server Components Flaw Lets Attackers Freeze Next.js Servers With a Single POST Request
- Simon Koeck - React RSC FormData Event Loop DoS write-up
- GitHub Security Advisory GHSA-rv78-f8rc-xrxh (facebook/react)
- NVD - CVE-2026-23870
- Wiz Vulnerability Database - CVE-2026-23870
- Red Hat CVE-2026-23870
- ZeroPath - CVE-2026-23870 React Server Components DoS analysis
- GitLab Advisory Database - react-server-dom-webpack CVE-2026-23870
Detection coverage for TL-2026-3096
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3096 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.