High-severity DoS in React Server Components (CVE-2026-23864) with incomplete prior fixes
React maintainers disclosed that earlier mitigations for denial-of-service issues in React Server Components were incomplete, leaving multiple DoS conditions still exploitable as CVE-2026-23864 (CVSS 7.5). The issue affects the react-server-dom-* packages used by bundlers—react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack—across versions 19.0.0–19.2.3. An attacker can send specially crafted HTTP requests to Server Function endpoints to drive resource exhaustion, potentially causing server crashes, out-of-memory conditions, or excessive CPU usage; applications that do not use a server-side React Server Components/Server Functions setup (e.g., purely client-side SPAs) are not impacted.
Vercel reported the vulnerabilities were responsibly disclosed and emphasized they do not enable RCE, but can still materially impact availability for affected deployments, including those using Next.js and other frameworks/bundlers that embed React Server Components. Vercel deployed new WAF rules to provide automatic mitigation for projects hosted on its platform, while warning that WAF protections are not a substitute for patching. Recommended remediation is to upgrade to patched releases: React 19.0.4, 19.1.5, 19.2.4, and updated downstream framework versions (including multiple Next.js fixed releases) as provided by maintainers.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
4 events from the most recent confirmed update back to the earliest known activity.
Vercel deploys WAF mitigations for all hosted projects
Vercel created and deployed new mitigation rules to the Vercel WAF to automatically protect all Vercel-hosted projects at no additional cost. The company emphasized that WAF protection alone was not sufficient and that customers should still upgrade to patched React and framework releases.
Next.js publishes fixes across supported branches
Downstream framework fixes were released for Next.js across multiple supported branches and canary versions to address the React Server Components denial-of-service issue. Users were advised to update framework versions in addition to relying on upstream React patches.
React issues advisory for CVE-2026-23864 and releases patched versions
React disclosed CVE-2026-23864, warning that earlier fixes were incomplete and that affected server-dom packages remained vulnerable across versions 19.0.0 through 19.2.3. The project released patched versions 19.0.4, 19.1.5, and 19.2.4 and urged developers to upgrade immediately.
Researchers responsibly disclose React Server Components DoS flaws
Multiple researchers from Winfunc Research, GMO Flatt Security, and Tencent Security YUNDING LAB responsibly disclosed high-severity denial-of-service vulnerabilities affecting React Server Components and Server Function endpoints. The flaws could be triggered with specially crafted HTTP requests to cause crashes, out-of-memory conditions, or excessive CPU usage, but were explicitly stated not to enable remote code execution.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
3 references tracked. Mallory keeps watching after this page renders.
Multiple Vulnerabilities in React Server Components Enable DoS Attacks
cybersecuritynews.com
Open sourceIncomplete Fix: High-Severity React Server Components DoS Flaw (CVE-2026-23864)
securityonline.info
Open sourceSummary of CVE-2026-23864 - Vercel
vercel.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.

