CVE-2026-23869Patch

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4). The vulnerability is triggered by sending specially crafted HTTP requests to Server Function endpoints.The payload of the HTTP request causes excessive CPU usage for up to a minute ending in a thrown error that is catchable.

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-502CWE-770

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 26 mentions across 9 observed days
  • Momentum state: declining

What's happening

  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 15 signals
  • Technical details provided in 18 signals
  • Disclosure: 11 classified signals
  • General: 2 classified signals
  • Peaked 7d ago at 9 mentions (2026-04-09); latest day: 1
  • 26 total mentions across 9 days

Deep dive

Activity timeline26 mentions / 9d
02579Mentions · 2026-04-08: 1Mentions · 2026-04-09: 9Mentions · 2026-04-10: 8Mentions · 2026-04-14: 1Mentions · 2026-04-15: 2Mentions · 2026-04-17: 2Mentions · 2026-04-20: 1Mentions · 2026-04-24: 1Mentions · 2026-04-25: 1PoC Mentioned / Linked · 2026-04-09: 2PoC Mentioned / Linked · 2026-04-10: 1Patch / Workaround · 2026-04-09: 5Patch / Workaround · 2026-04-10: 5Patch / Workaround · 2026-04-17: 2Patch / Workaround · 2026-04-20: 1Patch / Workaround · 2026-04-24: 1Patch / Workaround · 2026-04-25: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-09: 6Technical Details · 2026-04-10: 4Technical Details · 2026-04-15: 2Technical Details · 2026-04-17: 2Technical Details · 2026-04-20: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 104-0804-0904-1004-1404-1504-1704-2004-2404-25
Signal classification3 categories
Patch
1350.0%
Disclosure
1142.3%
General
27.7%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-04-081
Disclosure1
2026-04-099
Disclosure6Patch3
2026-04-108
Disclosure2General1Patch5
2026-04-141
Disclosure1
2026-04-152
Disclosure1General1
2026-04-172
Patch2
2026-04-201
Patch1
2026-04-241
Patch1
2026-04-251
Patch1
Full discourse20 posts
  • ︎︎🐸いまいまい🐌@imaimai17468
    Disclosure

    2026年4月8日、React Server Components に新たな脆弱性(CVE-2026-23869)が公開されました。CVSS スコアは 7.5 で、深刻度は高に分類されます。 何が起きたか Next.js の App Router が使用する React Server Components の処理に欠陥があります。攻撃者が細工した HTTP リクエストを App Router の Server Function エンドポイントに送信すると、デシリアライズ時にサーバーの CPU 使用率が異常に上昇し、サービスが停止する可能性があります。認証は不要で、外部から攻撃を行うことができます。対象は Next.js 13.x、14.x、15.x、16.x で App Router を使用しているアプリケーションです。Pages Router のみを使用している場合は影響を受けません。 2025年末の脆弱性との違い 2025年12月に公開された CVE-2025-55182(通称 React2Shell)は、同じ React Server Components の仕組みを悪用するものでしたが、サーバー上で任意のコードを実行できる脆弱性でした。深刻度は最高値の CVSS 10.0 で、実際に悪用された事例も報告されています。今回の CVE-2026-23869 はコードの実行には至らず、サービスの停止にとどまります。根本的な原因は同じデシリアライズ処理の設計にあり、React2Shell 以降も研究者による調査が続いた結果、関連する欠陥が順次発見されています。 対応すること Next.js を以下のバージョンに更新してください。15 系を使用している場合は 15.5.15 以降、16 系を使用している場合は 16.2.3 以降が修正済みのバージョンです。Vercel にホストしている場合は WAF による緩和措置が自動適用されていますが、バージョンアップの代替にはなりません。更新後は動作確認を行い、問題がなければ本番環境に適用してください。

    Post summary

    The text discloses a new CVE‑2026‑23869 affecting React Server Components, detailing its impact, severity, and patch recommendations.

    21011755432491.1K
    5.9K followersView on X
  • Cloudforce One@Cloudforce_One
    Patch

    Cloudflare offers proactive protection against CVE-2026-23869 through existing WAF rule aaede80b4d414dc89c443cea61680354.

    Post summary

    Cloudflare offers mitigation for CVE-2026-23869 by deploying an existing WAF rule, providing immediate protection.

    41101514532.1K
    3.1K followersView on X
  • yousukezan@yousukezan
    Patch

    React Server Componentsに高深刻度の脆弱性が見つかり、細工されたHTTPリクエストだけでCPUを過剰消費させサービス停止に追い込む恐れがある。Next.js広範囲に影響し緊急対応が求められる。 問題はCVE-2026-23869として追跡されており、App RouterのServer Functionに特定のリクエストを送ることでデシリアライズ処理時に異常なCPU負荷を引き起こす。影響範囲はNext.js 13系から16系までと広く、未修正環境ではサービス拒否攻撃が成立する可能性がある。VercelはWAFに新たな防御ルールを導入し全プロジェクトへ自動適用したが、これは補助的対策に過ぎず根本的な防御にはならない。修正版のReactおよび関連フレームワークでは問題が解消されており、開発者は速やかなアップデートが不可欠である。攻撃は特別な権限を必要とせず外部から実行可能であり、公開サービスほど影響が大きいとみられる。 https://vercel.com/changelog/summary-of-cve-2026-23869

    Post summary

    The post announces a high‑severity CVE‑2026‑23869 affecting Next.js, details the exploit vector, and urges developers to apply the released fixes, while additional WAF rules are in place.

    024177359.8K
    14.3K followersView on X
  • Ron Masas@RonMasas
    Disclosure

    The best security research starts where someone else's ended. Remember React2Shell? @SillamYohann picked up where it left off and found CVE-2026-23869, a single HTTP request that can freeze your React server for minutes. Here's how. 🧵

    Post summary

    The text announces the discovery of CVE‑2026‑23869, describing a single HTTP request that can freeze a React server for minutes, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    11041639
    1.6K followersView on X
  • JSer.info@jser_info
    Patch

    "Summary of CVE-2026-23869 - Vercel" https://realtime.jser.info/2026/04/10/summary-of-cve-2026-23869-vercel/ → https://vercel.com/changelog/summary-of-cve-2026-23869 React Server Components(RSC)のDoS脆弱性の修正としてNext.js 15.5.15/16.2.3とReact 19.2.5がリリースされて

    Post summary

    CVE‑2026‑23869 is a DoS flaw in React Server Components; Vercel addressed it with updates to Next.js 15.5.15/16.2.3 and React 19.2.5.

    01041884
    4.3K followersView on X
  • 도연@doyoniiii_
    Patch

    CVE-2026-23869 전체 패치 완료!

    Post summary

    The text announces that the patch for CVE‑2026‑23869 has been fully applied, confirming patch availability and completion.

    00040199
    720 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: High vulnerability in #React Server Components. CVE-2026-23869 CVSS: 7.5. This can lead to a denial of service #DoS #Patch #Patch #Patch

    Post summary

    The post warns of a medium‑to‑high severity denial‑of‑service vulnerability (CVE‑2026‑23869) in React Server Components, urging users to apply the available patch.

    01011235
    7.2K followersView on X
  • Yohann Sillam@SillamYohann
    General

    Definitely true ( serializer only traverses what you explicitly pass ), but an unauthenticated actor still has surprising degree of freedom to traverse that object root & run aggregators on it and cause heavy computation on the server side (CVE-2026-23869). Tried the same kind of idea on Livewire: I didn't succeed because 1. The protocol is much less powerful and 2. They ship a signed checksum to the client. But I'm not sure if this idea is exploitable with RSC... https://github.com/livewire/livewire/blob/main/src/Mechanisms/HandleComponents/Checksum.php

    Post summary

    The tweet discusses a potential denial‑of‑service vulnerability (CVE‑2026‑23869) via object traversal but offers no PoC, exploit, patch, or evidence of active exploitation.

    00021470
    11 followersView on X
  • Cyber Kendra@cyberkendra
    Disclosure

    🚨 NEW: A high-severity flaw in #React Server Components (CVE-2026-23869) can take down your server with a SINGLE HTTP request — no login needed. Researchers dubbed it "React2DoS." Here's what you need to know 🧵 https://t.co/1xvkKupb2h

    Post summary

    The tweet announces a newly discovered high‑severity denial‑of‑service flaw in React Server Components (CVE‑2026‑23869) that can bring a server down with a single HTTP request, without providing PoC or exploit details.

    10020235
    1.5K followersView on X
  • Jack Herrington@jherr
    Disclosure

    @AyushAgrawal_A2 @tan_stack NextJS definitely still has CVE vulnerabilities on the same mechanism of R2S. Here is one from four days ago: https://nvd.nist.gov/vuln/detail/CVE-2026-23869

    Post summary

    The tweet alerts to recent CVE-2026-23869 affecting NextJS, highlighting its existence, but offers no technical details, exploits, or patch information.

    10010252
    29.9K followersView on X
  • gawa@gawa_nazo
    Patch

    >RT NextのApp Router使ってる人はバージョンアップしといた方が良さそう。 システムが攻撃で止まる可能性あるとの事 (CVE-2026-23869)

    Post summary

    The tweet urges users of Next's App Router to upgrade due to CVE‑2026‑23869, indicating a patch or update is required to prevent potential system stoppage.

    00020403
    647 followersView on X
  • iototsecnews@iototsecnews
    Patch

    React Server コンポーネントの脆弱性 CVE-2026-23869 が FIX:低複雑性の未認証 DoS 攻撃 https://iototsecnews.jp/2026/04/10/react-server-components-vulnerability-enables-dos-attacks/ この脆弱性の原因は、React Server Components (RSC) がクライアントからの入力をデシリアライズする際の、不十分なサニタイズにあります。具体的には、サーバ上の関数を呼び出すエンドポイントにおいて、攻撃者が送り込んだ巨大な数値データや、複雑な構造のデータを制限なく処理するという不備がありました。この脆弱性 CVE-2026-23869 により、一度のリクエストでサーバの CPU を長時間にわたり占有し、リソースを枯渇させる攻撃が可能になっています。ご利用のチームは、ご注意ください。 #CVE202623869 #ReactServer #Vulnerability

    Post summary

    The article announces a fix for CVE-2026-23869, explaining that unsanitized deserialization in React Server Components can lead to CPU exhaustion DoS attacks, but it does not provide PoC, exploit code, or evidence of active exploitation.

    01000157
    484 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    React Server ComponentsにDoS脆弱性 CVE-2026-23869 https://rocket-boys.co.jp/security-measures-lab/react-server-components-dos-cve-2026-23869/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    This post announces CVE-2026‑23869 as a DoS vulnerability impacting React Server Components, without providing any proof‑of‑concept, exploit, or fix information.

    00010138
    380 followersView on X
  • omvapt@omvapt
    Disclosure

    #React2DoS (CVE-2026-23869): When the Flight Protocol Crashes at Takeoff https://buff.ly/jvTPoh1 https://t.co/2iIG2heHMN

    Post summary

    The tweet announces CVE‑2026‑23869 as a DoS flaw in the Flight Protocol that causes crashes, but it provides no PoC, exploit details, patch information, or evidence of active exploitation.

    00010110
    375 followersView on X
  • Mr.Rabbit@01ra66it
    Disclosure

    【React2DoS(CVE-2026-23869)、RSCのFlight Protocolに高深刻度DoS】 Impervaが、React Server ComponentsのFlight Protocolに起因する未認証DoS脆弱性「React2DoS(CVE-2026-23869)」を公開。 細工した参照関係を持つ小さなペイロードで、サーバー側に不釣り合いに重い計算を強制し、長時間の処理遅延や停止を引き起こし得るとされています。 以前のCVE-2026-23864より少ないペイロードでも高負荷化しやすい点が重要。 影響はReact Server Components 19.2.4以下で、修正版は19.2.5です。RSC採用環境は早急な更新確認を進めたい事案です。 #CyberSecurity #React #RSC #DoS #CVE202623869 https://www.imperva.com/blog/react2dos-cve-2026-23869-when-the-flight-protocol-crashes-at-takeoff/

    Post summary

    Imperva disclosed CVE‑2026‑23869, an unauthenticated DoS in React Server Components, detailing the attack payload and urging updates to the patched 19.2.5 release.

    00001475
    3.5K followersView on X
  • izawa ryosuke✈️SF 4/22~4/25@e_san_desuyo
    Disclosure

    CVE-2026-23869 ReactのいつくかのパッケージでDos脆弱性を検知 パッケージ📦 react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack バージョン👨‍💻 19.0.0~19.0.4, 19.1.0~19.1.5, 19.2.0~19.2.4 https://www.cve.org/CVERecord?id=CVE-2026-23869

    Post summary

    CVE-2026-23869 is a denial‑of‑service vulnerability that affects several React server‑DOM packages across multiple version ranges.

    00010314
    1.7K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    React patches a 7.5 CVSS DoS vulnerability in Server Components (CVE-2026-23869). Stop CPU exhaustion attacks—update your 19.x dependencies now! #ReactJS #RSC #CyberSecurity #WebDev #InfoSec #CVE202623869 #JavaScript https://securityonline.info/react-server-components-dos-vulnerability-cve-2026-23869/ https://t.co/ds9PmhtrW6

    Post summary

    The post announces that React has patched a 7.5‑scored DoS flaw in Server Components (CVE‑2026‑23869) and advises developers to upgrade to the 19.x series.

    00001471
    11.1K followersView on X
  • VibeShield.me@vibeshield
    Patch

    🚨 CVE-2026-23869 crashes Next.js apps via malicious requests. AI tools ship React Server Components by default, risking vibecoded apps. Update Next.js to latest patch now. VibeShield scans check it. Don't let bad requests kill your launch. #NextJS

    Post summary

    The tweet warns about CVE-2026-23869 causing crashes in Next.js via malicious requests and recommends applying the latest patch to mitigate the issue.

    0000042
  • VibeShield.me@vibeshield
    Patch

    🚨 New Next.js patch fixes CVE-2026-23869 (React Server Components DoS). Vulnerable apps risk downtime under attack. Update released 10h ago. Run npm update now. VibeShield catches these outdated deps in scans. Keep your stack fresh. 🔐 #NextJS

    Post summary

    The announcement informs users about a new Next.js patch that addresses CVE-2026-23869, a DoS vulnerability in React Server Components, and urges a run of npm update within 10 hours.

    0000048
  • ChangeWatch@changewatchdev
    Patch

    Vercel deploys WAF mitigations for CVE-2026-23869 — upgrade Next.js If you run Next.js apps that use the App Router (Server Function endpoints), a high‑severity vulnerability (CVE-2026-23869, CVSS 7.5) can allow a specially crafted HTTP… Read more → http://changewatch.dev/explore/789d813f-3fd3-4aed-95e2-8ce941c6d827

    Post summary

    Vercel has deployed WAF mitigations for the high‑severity CVE‑2026‑23869, urging Next.js users to upgrade as a patch.

    0000078
    3 followersView on X

Explore more