CVE-2026-23864General(facebook / react)

MEDIUMCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch facebook react systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending specially crafted HTTP requests to Server Function endpoints, and could lead to server crashes, out-of-memory exceptions or excessive CPU usage; depending on the vulnerable code path being exercised, the application configuration and application code. Strongly consider upgrading to the latest package versions to reduce risk and prevent availability issues in applications using React Server Components.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-502CWE-1284

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • react

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 24 mentions across 14 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 14 signals
  • General: 8 classified signals
  • Disclosure: 8 classified signals
  • Peaked 12d ago at 6 mentions (2026-01-28); latest day: 1
  • 24 total mentions across 14 days

Affected systems

Vendors
Products
react

Deep dive

Activity timeline24 mentions / 14d
02356Mentions · 2026-01-27: 3Mentions · 2026-01-28: 6Mentions · 2026-01-29: 4Mentions · 2026-01-30: 1Mentions · 2026-02-01: 1Mentions · 2026-02-02: 1Mentions · 2026-02-05: 1Mentions · 2026-02-26: 1Mentions · 2026-03-05: 1Mentions · 2026-03-18: 1Mentions · 2026-04-09: 1Mentions · 2026-04-10: 1Mentions · 2026-04-21: 1Mentions · 2026-05-07: 1Active Exploitation · 2026-01-28: 1Patch / Workaround · 2026-01-28: 3Patch / Workaround · 2026-01-29: 1Patch / Workaround · 2026-01-30: 1Patch / Workaround · 2026-02-02: 1Patch / Workaround · 2026-02-05: 1Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-04-10: 1Technical Details · 2026-01-28: 5Technical Details · 2026-01-29: 4Technical Details · 2026-01-30: 1Technical Details · 2026-02-02: 1Technical Details · 2026-02-26: 1Technical Details · 2026-03-18: 1Technical Details · 2026-04-09: 101-2701-2801-2901-3002-0102-0202-0502-2603-0503-1804-0904-1004-2105-07
Signal classification4 categories
General
833.3%
Disclosure
833.3%
Patch
729.2%
Active Exploitation
14.2%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-01-273
General3
2026-01-286
Active Exploitation1Disclosure2Patch3
2026-01-294
Disclosure3Patch1
2026-01-301
Patch1
2026-02-011
General1
2026-02-021
Disclosure1
2026-02-051
Patch1
2026-02-261
General1
2026-03-051
Disclosure1
2026-03-181
Patch1
2026-04-091
General1
2026-04-101
Disclosure1
2026-04-211
General1
2026-05-071
General1
Full discourse20 posts
  • Cloudflare Changelog@CFchangelog
    Active Exploitation

    🛡️ New WAF detections are here! We're now blocking denial-of-service attempts targeting React (CVE-2026-23864) to keep your apps running smoothly. Enhanced protection for React Server! 🚀 https://developers.cloudflare.com/changelog/2026-01-26-waf-release/

    Post summary

    Cloudflare’s new WAF detections now block denial‑of‑service attacks exploiting CVE‑2026‑23864 in React, confirming it is actively used in the wild.

    0102131.8K
    2.8K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    React Server Componentsでまた脆弱性が修正。CVE-2026-23864は無認証で細工されたHTTPリクエストをServer Functionエンドポイントに投げると実装側依存でDoS。 https://vercel.com/changelog/summary-of-cve-2026-23864

    Post summary

    The text announces that Vercel has fixed an unauthenticated DoS vulnerability (CVE‑2026‑23864) in React Server Components, with patch details available in the referenced changelog.

    01052735
    7.2K followersView on X
  • Khashayar Fereidani@fereidani
    General

    React project name came from the fact that developer must constantly react to the extreme software vulnerabilities introduced by using it. CVE-2026-23864

    Post summary

    A React project name references CVE-2026-23864, but no technical details, PoC, or exploitation info are provided.

    00030114
    105 followersView on X
  • Ron Masas@RonMasas
    General

    How does it compare to CVE-2026-23864? That one needed a 1MB payload to stall the server for seconds. React2DoS achieves minutes of computation with tens of kilobytes. https://t.co/laGOF3cDLv

    Post summary

    The text compares the payload size and server stall time of React2DoS to CVE-2026-23864, noting that React2DoS achieves longer computation times with a much smaller payload.

    10010125
    1.5K followersView on X
  • Rafael Coelho@coelho_lab_
    General

    eu quero eh novidade. eu fique surpreso pela demora. ja e 27 de janeiro https://vercel.com/changelog/summary-of-cve-2026-23864 @sseraphini

    Post summary

    The user simply notes the existence of CVE‑2026‑23864 with a link to a Vercel changelog, providing no further details on the vulnerability or its exploitation.

    01010415
    749 followersView on X
  • Cyber Kendra@cyberkendra
    Disclosure

    4/ This is the third Flight protocol vuln this year after #React2Shell and CVE-2026-23864. React's server architecture is under a microscope. If you run RSC in production, patching is non-negotiable. Read Details👇 https://www.cyberkendra.com/2026/04/react2dos-flaw-can-crash-servers-with.html #react2dos #security #webdev

    Post summary

    The tweet announces a third Flight protocol vulnerability affecting React’s server architecture this year, emphasizing the necessity of applying patches.

    0001097
    1.5K followersView on X
  • Grok@grok
    Patch

    Intel collected: RSC: React2Shell (CVE-2025-55182, CVSS 10) enabled unauth RCE via crafted server function payloads. Follow-up DoS (CVE-2026-23864) causes OOM/crashes/CPU spikes in pre-19.2.4. Patch React to 19.2.4+ immediately. LLM sec (per jhaddix intel): Arcanum LLM Security Context Project (150+ sources) for safer code gen. Risks: prompt injection hijacks agent identity/personality; unsafe outputs trigger XSS/exec; secrets leak via prompts/context. Tiered defenses > basic jailbreaks. No rez0 hits. Update & sanitize.

    Post summary

    Intel reports CVE‑2025‑55182 and CVE‑2026‑23864 in React, providing technical details and recommending an immediate patch to version 19.2.4+.

    00010119
    8.5M followersView on X
  • React Weekly@ReactWeeklyDev
    Disclosure

    Stop what you’re doing and check your versions. 🛠️ A high-severity Denial of Service (DoS) vulnerability (CVE-2026-23864) has been found in the RSC 'Flight' protocol. It can trigger CPU/memory exhaustion with a single crafted request. Whether you're on Next.js or Vite patch Now

    Post summary

    A high‑severity DoS vulnerability (CVE‑2026‑23864) affecting the RSC 'Flight' protocol can cause CPU/memory exhaustion with a single crafted request, and users are urged to apply the available patch.

    1000073
    50 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    React Server ComponentsでDoS脆弱性(CVE-2026-23864) https://rocket-boys.co.jp/security-measures-lab/react-server-components-dos-vulnerability-cve-2026-23864/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The article announces a DoS vulnerability in React Server Components (CVE-2026-23864) but provides no PoC, exploit, or patch information.

    01000179
    318 followersView on X
  • Abhishek Verma@pyvrma
    Disclosure

    1/ 🚨 CVE-2026-23864: A high-severity (CVSS 7.5) Denial of Service vulnerability found in React Server Components. Specially crafted HTTP requests can trigger server crashes or memory exhaustion. No RCE was found, but immediate action is required. https://t.co/NMLSqscfHm

    Post summary

    The tweet announces CVE-2026-23864, a Denial-of-Service vulnerability in React Server Components with CVSS 7.5, requiring immediate attention but providing no PoC, exploit, or patch details.

    10000280
    1.0K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-23864: React Server Components Denial-of-Service Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04cTyfn0

    Post summary

    The text references CVE-2026-23864 but provides no concrete details, exploitation evidence, mitigation steps, or technical specifics.

    000009
    29 followersView on X
  • Komodo Cyber Security@Komodosec
    Disclosure

    #VulnerabilityReport #CVE202623864 Incomplete Fix: High-Severity React Server Components DoS Flaw (CVE-2026-23864) https://securityonline.info/incomplete-fix-high-severity-react-server-components-dos-flaw-cve-2026-23864/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The post announces an incomplete fix for the high‑severity CVE‑2026‑23864 DoS flaw in React Server Components, but does not provide PoC, exploit code, or evidence of active exploitation.

    0000029
    1.5K followersView on X
  • Rodrigo Moreno@RodMoreno_
    General

    • CVE-2025-55183 — Source code exposure. • CVE-2026-23864 — Another DoS, CVSS 7.5, January 2026. The glass house was yours, @rauchg.

    Post summary

    The text lists two CVEs with brief vulnerability descriptions but provides no actionable details such as PoC, exploit, or patch information.

    0000059
    317 followersView on X
  • Grok@grok
    Patch

    Smart approach to maintenance—focusing iterations on model updates keeps things efficient. Vercel indeed rolled out patches for React/Next.js vulns like CVE-2026-23864 in Jan 2026. Netlify did too, with fixes for similar React issues in Dec 2025 and Jan 2026, so your projects there are likely covered. Any plans for new AI-driven ones?

    Post summary

    Vercel and Netlify have released patches for React/Next.js vulnerabilities, including CVE‑2026‑23864, effectively covering projects hosted on those platforms.

    0000052
    8.1M followersView on X
  • EIonAI@EIon_AI
    General

    weeeeeeeeee CVE-2026-23864 yolo! I hope the creator set a budget

    Post summary

    The text casually mentions CVE-2026-23864 without providing any technical details, PoC, exploit code, or actionable information.

    0000080
    17 followersView on X
  • VulnTracker@vuln_tracker
    Patch

    Did you catch this CVE? 🚨 CVE-2026-23864 Alert 🚨 High-severity Denial of Service (DoS) flaw in React Server Components affects: react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-parcel. Malicious HTTP requests to Server Function endpoints can cause crashes, memory exhaustion, or high CPU usage — update to patched versions now! Track CVEs like this automatically → http://vulntracker.io 🔒 #CVE #ReactJS #Infosec #NodeJS

    Post summary

    CVE‑2026‑23864 is a high‑severity DoS vulnerability affecting React Server Components; users are advised to upgrade to patched versions immediately.

    00000214
    335 followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Disclosure

    React Server ComponentsでDoS脆弱性(CVE-2026-23864) https://rocket-boys.co.jp/security-measures-lab/react-server-components-dos-vulnerability-cve-2026-23864/

    Post summary

    The post announces a new denial‑of‑service vulnerability (CVE‑2026‑23864) in React Server Components, but provides no PoC, exploit, or mitigation details.

    00000160
    45 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-23864: React Server Components: The Flight to Nowhere (CVE-2026-23864) Multiple Denial of Service (DoS) and Prototype Pollution vulnerabilities exist in the React Server Components (RSC) 'Flight' protocol implementation. These flaws allow att... https://cvereports.com/reports/CVE-2026-23864

    Post summary

    The post announces the discovery of multiple DoS and prototype‑pollution flaws in React Server Components' Flight protocol, providing technical details but no evidence of exploitation or mitigations.

    00000104
    29 followersView on X
  • ノグオ・ワールドピース@Likeagorira
    Patch

    1月26日に公開されたReact Server ComponentsにおけるDoS脆弱性ダヨ‼️オジサン不安💦💦😅 https://vercel.com/changelog/summary-of-cve-2026-23864 # 影響内容 特定の細工されたHTTPリクエストを送信されることで、サーバーのクラッシュ、メモリ不足エラー、過剰なCPU使用などが引き起こされる可能性😳⁉️ヤバ💦😅 # 影響を受けるパッケージとバージョン 次のパッケージのバージョン19.0.x, 19.1.x, 19.2.x (バージョンイクイクってことカナ❓σ(^^;)ナンチャッテ) ①react-server-dom-parcel ②react-server-dom-webpack ③react-server-dom-turbopack ↑は以下のフレームワークに含まれてるヨ‼️😅😅😅 - Next.js: 13.x, 14.x, 15.x, 16.x - その他、RSCを利用するフレームワーク(Vite, Parcel, React Router, Wakuなど) # 対策 以下のバージョン(またはそれ以降)へ速やかにアップグレード⤴️しましょうネ‼️ - React: 19.0.4, 19.1.5, 19.2.4 - Next.js: 15.0.8, 15.1.12, 15.2.9, 15.3.9, 15.4.11, 15.5.10 16.0.11, 16.1.5 バージョンアップしてお寿司🍣でも食べに行こうネ😆👍

    Post summary

    CVE-2026-23864 is a DoS vulnerability in React Server Components that can cause server crashes and high CPU usage from crafted HTTP requests; the advisory recommends upgrading to the specified patched versions of React and Next.js.

    00000143
    85 followersView on X
  • Miguel Vera@mveracf
    Patch

    React apps just got a security boost! 🛡️ Our WAF now blocks denial-of-service attempts targeting React (CVE-2026-23864). Keeping your sites running smoothly & securely. 💪 https://developers.cloudflare.com/changelog/2026-01-26-waf-release/

    Post summary

    Cloudflare announces a WAF update that blocks denial‑of‑service attempts against React apps tied to CVE‑2026‑23864, providing a mitigation for the vulnerability.

    00000103
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfacebookreact---

Explore more