Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
open-source-dependency-vulnerabilitywidely-deployed-product-advisoryinternet-facing-service-vulnerabilitypatch-regression

High-severity DoS in React Server Components (CVE-2026-23864) with incomplete prior fixes

Updated 3mo agoFirst seen Jan 27, 20263 sources

React maintainers disclosed that earlier mitigations for denial-of-service issues in React Server Components were incomplete, leaving multiple DoS conditions still exploitable as CVE-2026-23864 (CVSS 7.5). The issue affects the react-server-dom-* packages used by bundlers—react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack—across versions 19.0.0–19.2.3. An attacker can send specially crafted HTTP requests to Server Function endpoints to drive resource exhaustion, potentially causing server crashes, out-of-memory conditions, or excessive CPU usage; applications that do not use a server-side React Server Components/Server Functions setup (e.g., purely client-side SPAs) are not impacted.

Vercel reported the vulnerabilities were responsibly disclosed and emphasized they do not enable RCE, but can still materially impact availability for affected deployments, including those using Next.js and other frameworks/bundlers that embed React Server Components. Vercel deployed new WAF rules to provide automatic mitigation for projects hosted on its platform, while warning that WAF protections are not a substitute for patching. Recommended remediation is to upgrade to patched releases: React 19.0.4, 19.1.5, 19.2.4, and updated downstream framework versions (including multiple Next.js fixed releases) as provided by maintainers.

Share:
High-severity DoS in React Server Components (CVE-2026-23864) with incomplete prior fixes
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Jan 26, 20265mo ago

Vercel deploys WAF mitigations for all hosted projects

Vercel created and deployed new mitigation rules to the Vercel WAF to automatically protect all Vercel-hosted projects at no additional cost. The company emphasized that WAF protection alone was not sufficient and that customers should still upgrade to patched React and framework releases.

Next.js publishes fixes across supported branches

Downstream framework fixes were released for Next.js across multiple supported branches and canary versions to address the React Server Components denial-of-service issue. Users were advised to update framework versions in addition to relying on upstream React patches.

React issues advisory for CVE-2026-23864 and releases patched versions

React disclosed CVE-2026-23864, warning that earlier fixes were incomplete and that affected server-dom packages remained vulnerable across versions 19.0.0 through 19.2.3. The project released patched versions 19.0.4, 19.1.5, and 19.2.4 and urged developers to upgrade immediately.

Researchers responsibly disclose React Server Components DoS flaws

Multiple researchers from Winfunc Research, GMO Flatt Security, and Tencent Security YUNDING LAB responsibly disclosed high-severity denial-of-service vulnerabilities affecting React Server Components and Server Function endpoints. The flaws could be triggered with specially crafted HTTP requests to cause crashes, out-of-memory conditions, or excessive CPU usage, but were explicitly stated not to enable remote code execution.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

11 LINKEDOpen in app
Affected products
3 linked
ReactVercelNext.Js
Organizations
7 linked
Western Digital CorporationTencentNvidiaGMO Flatt SecurityMinioVercelWinfunc Research
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.