Threat reportVulnerabilityTL-2026-3096

React Server Components DoS Vulnerability (CVE-2026-23870) Lets Attackers Freeze Next.js Servers With a Single POST Request

highACTIVE

React Server Components DoS Vulnerability (CVE-2026-23870) (TL-2026-3096) is a high-severity software vulnerability scored CVSS 7.5, first published 2026-10-09. It has no confirmed attribution, affects Meta (Facebook) react-server-dom-webpack, references 1 CVE (CVE-2026-23870), maps to 8 MITRE ATT&CK techniques (T1190, T1499, T1499.003), and is covered by 9 detection rules and 12 indicators of compromise.

CVSS
7.5/10High
CVEs
1Referenced vulnerabilities
Techniques
8MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
12Indicators of compromise

Key facts for TL-2026-3096

Threat ID
TL-2026-3096
Severity
HIGH
CVSS
7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, ecommerce, finance, news - media, saas
Target regions
Global
Detection rules
9
Indicators of compromise
12
Updates
2026-10-09 · revalidated 1× · latest source

Malware and tooling in React Server Components DoS Vulnerability (CVE-2026-23870)

Malware and tooling: Public GitHub PoC for CVE-2026-23870 (runnable scripts targeting Next.js 16.2.4)

How React Server Components DoS Vulnerability (CVE-2026-23870) works

CVE-2026-23870 is an unauthenticated denial-of-service flaw (CWE-400/CWE-770) in the React Server Components packages react-server-dom-webpack, react-server-dom-turbopack and react-server-dom-parcel. A crafted ~900 KB multipart POST to a Server Function endpoint forces quadratic form-data processing that blocks the Node.js event loop. Fixed in React 19.0.6, 19.1.7 and 19.2.6; a public PoC exists but no in-the-wild exploitation is reported.

CVE-2026-23870 affects the React Server Components (RSC) server-side packages react-server-dom-webpack, react-server-dom-turbopack and react-server-dom-parcel in React 19.0.0-19.0.5, 19.1.0-19.1.6 and 19.2.0-19.2.5. The CVE was assigned by Meta and carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The advisory (GHSA-rv78-f8rc-xrxh) lists CWE-400 and CWE-770; Red Hat classifies it as CWE-770. Applications are exposed only if they run server-side React code through a framework or bundler that supports React Server Components (for example Next.js, React Router, Waku, @parcel/rsc, @vitejs/plugin-rsc, rwsdk).

Root cause (per researcher Simon Koeck's write-up): when React rebuilds form data for a Server Action/Server Function request, it resolves each $K pointer (a reference marker for a nested form) by walking the entire list of request fields and matching names against a prefix. There was no cap on either the number of pointers or the number of fields, so the cost is quadratic. A request with 10,000 $K pointers and 10,000 filler fields forces about 100 million string comparisons.

Proof of concept: the payload uses 10,000 $K pointers nested one level deep, which avoids the argument-count limits. They sit under $ACTION_0:2 to avoid the nesting-depth restrictions, and are paired with 10,000 filler fields. The total request is about 900 KB. The attacker needs no authentication; the Server Action ID can be extracted from the target's served HTML/JavaScript. Reported impact: about 4 seconds of server freeze for a single request on a production build on a laptop, and about 10 seconds per request on production infrastructure. Three sequential requests triggered load-balancer failover. Because Node.js is single-threaded, the event loop is blocked and other requests queue or time out. Symptoms are CPU saturation, HTTP 503/timeouts and failed health checks that can remove nodes from load balancers. Advisory text also notes out-of-memory exceptions or process termination are possible.

Fix: React changed the logic to traverse the form data once per request, using a bookmark that tracks position and deletes consumed fields, which removes the quadratic behavior. Patched releases are 19.0.6, 19.1.7 and 19.2.6. Red Hat reports no practical mitigation other than upgrading. Defense-in-depth recommended by the source article: POST body-size limits, request-rate controls and timeouts, and monitoring for unusual POST activity against Server Action endpoints.

Context: this follows earlier RSC denial-of-service disclosures (December 2025 DoS and source-code exposure; CVE-2026-23864 in January 2026 for an incomplete fix; CVE-2026-23869 and CVE-2026-23870 in May 2026). Wiz reports the CVE is not in the CISA KEV catalog, with no confirmed in-the-wild exploitation, and a public PoC on GitHub targeting Next.js 16.2.4. No threat actor attribution or network IOCs are published.

MITRE ATT&CK techniques used in TL-2026-3096

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1499 Endpoint Denial of Service; T1499.003 Endpoint Denial of Service: Application Exhaustion Flood; T1499.004 Endpoint Denial of Service: Application or System Exploitation

Resource Development

T1587.004 Develop Capabilities: Exploits; T1588.006 Obtain Capabilities

Reconnaissance

T1592.002 Gather Victim Host Information; T1594 Search Victim-Owned Websites

Affected products and versions in React Server Components DoS Vulnerability (CVE-2026-23870)

  • Meta (Facebook) — react-server-dom-webpack
    Vulnerable versions: 19.0.0-19.0.5; 19.1.0-19.1.6; 19.2.0-19.2.5
    Fixed in: 19.0.6; 19.1.7; 19.2.6
  • Meta (Facebook) — react-server-dom-turbopack
    Vulnerable versions: 19.0.0-19.0.5; 19.1.0-19.1.6; 19.2.0-19.2.5
    Fixed in: 19.0.6; 19.1.7; 19.2.6
  • Meta (Facebook) — react-server-dom-parcel
    Vulnerable versions: 19.0.0-19.0.5; 19.1.0-19.1.6; 19.2.0-19.2.5
    Fixed in: 19.0.6; 19.1.7; 19.2.6

Remediation for React Server Components DoS Vulnerability (CVE-2026-23870)

Patches

  • React 19.0.6
  • React 19.1.7
  • React 19.2.6

Immediate actions

  • Upgrade react-server-dom-webpack, react-server-dom-turbopack and react-server-dom-parcel to 19.0.6, 19.1.7 or 19.2.6 (or the matching patched framework release)
  • Enforce POST body-size limits at the reverse proxy / CDN / WAF in front of Server Action endpoints
  • Apply request-rate controls and request timeouts on Server Function endpoints

Workarounds

  • No vendor workaround is available (Red Hat: mitigation not available); body-size limits, rate limiting and timeouts only reduce impact

Longer-term hardening

  • Monitor for unusual POST activity (large multipart bodies, many $K / $ACTION_ fields) against Server Action endpoints
  • Alert on event-loop lag, sustained CPU saturation and health-check failures on Node.js SSR workloads
  • Maintain an inventory of applications using React Server Components and track React security advisories

CVEs associated with React Server Components DoS Vulnerability (CVE-2026-23870)

CVE-2026-23870

Weaknesses (CWE) in React Server Components DoS Vulnerability (CVE-2026-23870)

CWE-400, CWE-770

Timeline of React Server Components DoS Vulnerability (CVE-2026-23870)

  • Initial React Server Components DoS and source-code exposure vulnerabilities disclosed, beginning the series of RSC advisories that includes CVE-2026-23870
  • CVE-2026-23864 identified as covering incomplete earlier RSC DoS fixes
  • CVE-2026-23869 (related RSC DoS, fixed in React 19.0.5/19.1.6/19.2.5 and Next.js 15.5.15/16.2.3) disclosed, preceding CVE-2026-23870
  • Simon Koeck reports the form-data $K pointer scanning DoS to Meta
  • React releases 19.0.6, 19.1.7 and 19.2.6; GHSA-rv78-f8rc-xrxh and CVE-2026-23870 (CVSS 7.5) published in NVD
  • Vercel ships the Next.js May 2026 security release (13 advisories) including the CVE-2026-23870 fix in Next.js 15.5.18 and 16.2.6; states no workarounds and no WAF rules
  • Next.js advisory GHSA-8h8q-6873-q5fj for CVE-2026-23870 published to OSV (CVSS 7.5, CWE-770)
  • NVD record for CVE-2026-23870 last modified
  • Simon Koeck publishes the technical write-up and ~900 KB PoC (10,000 $K pointers + 10,000 filler fields)
  • Cyber Security News reports the flaw can freeze Next.js servers with a single POST request; no in-the-wild exploitation reported

Update history for TL-2026-3096

Sources cited for React Server Components DoS Vulnerability (CVE-2026-23870)

Detection coverage for TL-2026-3096

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3096 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
12 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats