CVE-2026-23870PoC(facebook / react-server-dom-parcel)

MEDIUMCVSS 7.5 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch facebook react-server-dom-parcel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.5, 19.1.0 through 19.1.6, and 19.2.0 through 19.2.5).

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • react-server-dom-parcel
  • react-server-dom-turbopack
  • react-server-dom-webpack

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 27 mentions across 12 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 7 signals
  • PoC mentioned or linked in 8 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 13 signals
  • Disclosure: 7 classified signals
  • Peaked 8d ago at 5 mentions (2026-05-09); latest day: 3
  • 27 total mentions across 12 days

Affected systems

Vendors
Products
react-server-dom-parcelreact-server-dom-turbopackreact-server-dom-webpack

Deep dive

Activity timeline27 mentions / 12d
01345Mentions · 2026-05-06: 1Mentions · 2026-05-07: 1Mentions · 2026-05-08: 3Mentions · 2026-05-09: 5Mentions · 2026-05-10: 5Mentions · 2026-05-11: 1Mentions · 2026-05-14: 1Mentions · 2026-05-15: 1Mentions · 2026-06-18: 4Mentions · 2026-07-04: 1Mentions · 2026-10-08: 1Mentions · 2026-10-09: 3PoC Mentioned / Linked · 2026-05-08: 1PoC Mentioned / Linked · 2026-05-09: 3PoC Mentioned / Linked · 2026-05-10: 3PoC Mentioned / Linked · 2026-05-11: 1Exploit Tool / Code · 2026-05-08: 1Exploit Tool / Code · 2026-05-09: 2Exploit Tool / Code · 2026-05-10: 3Exploit Tool / Code · 2026-05-11: 1Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-05-08: 2Patch / Workaround · 2026-05-09: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-08: 2Technical Details · 2026-05-09: 3Technical Details · 2026-05-10: 1Technical Details · 2026-05-15: 1Technical Details · 2026-06-18: 3Technical Details · 2026-07-04: 105-0605-0705-0805-0905-1005-1105-1405-1506-1807-0410-0810-09
Signal classification4 categories
PoC
834.8%
Disclosure
730.4%
Patch
417.4%
General
417.4%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-05-061
Disclosure1
2026-05-071
Patch1
2026-05-083
Patch2PoC1
2026-05-095
Disclosure1Patch1PoC3
2026-05-105
General2PoC3
2026-05-111
PoC1
2026-05-141
General1
2026-05-151
Disclosure1
2026-06-184
Disclosure3General1
2026-07-041
Disclosure1
Full discourse20 posts
  • dw1@dwisiswant0
    PoC

    CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572 https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    A GitHub repository containing proof‑of‑concept code for multiple CVEs is referenced, with no indications of active exploitation, patches, or false‑positive claims.

    4126765045576.6K
    16.0K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    The text announces a GitHub repository containing proof‑of‑concept code for a series of Next.js CVEs, with no mention of patching, active exploitation, or debunking.

    144220813713.7K
    158.6K followersView on X
  • Psycho 🎭@Psycho10k_
    PoC

    Next.js v16.2.4 Security PoC Collection CVE-2026-23870 CVE-2026-44575 CVE-2026-44579 CVE-2026-44574 CVE-2026-44578 CVE-2026-44573 CVE-2026-44581 CVE-2026-44580 CVE-2026-44577 CVE-2026-44576 CVE-2026-44582 CVE-2026-44572 https://github.com/dwisiswant0/next-16.2.4-pocs via: Pr0xy

    Post summary

    The post lists several CVEs and points to a GitHub repository containing proof‑of‑concept code for Next.js v16.2.4, indicating PoC availability but no evidence of active exploitation or fixes.

    08043302.5K
    455 followersView on X
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-23870: DoS in React Server Components, 7.5 rating 🔥 DoS vulnerability in React Server Components allows an attacker to disable the web application by exhausting server resources. This vulnerability requires a specific architectural setup to be exploited. 👉 https://nt.ls/akCFc

    Post summary

    The post announces a new Denial‑of‑Service vulnerability (CVE‑2026‑23870) in React Server Components that can exhaust server resources and requires a particular architecture, but no PoC, exploit, patch, or active exploitation is reported.

    03018131.3K
    7.6K followersView on X
  • termireum@termireum
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    A GitHub repository containing Proof of Concept code for a dozen Next.js v16.2.4 CVEs is shared, with no evidence of active exploitation or patch information.

    0101810684
    758 followersView on X
  • Kyohei - OSS, 外資IT@labelmake
    PoC

    CVE-2026-23870 に関してRSCのFlightデシリアライズを利用したDoS脆弱性で、悪用難易度もreact2shellとほぼ同等 react2shellが公開された時に確実に同じようなハックが見つかるだろうと思っていたけどこれがそれです。 マネージドサービスで動かしている場合はWAFが守ってくれるが、Flightプロトコルの弱点を突く攻撃は完全に塞ぐのが難しいはずなので今後もウォッチしていく必要がある。

    Post summary

    The post confirms a proof‑of‑concept was discovered for CVE-2026-23870, a DoS vulnerability in RSC Flight deserialization, noting its difficulty is similar to react2shell but no exploit code or patch is detailed.

    110853.3K
    8.5K followersView on X
  • Cyber Security News@The_Cyber_News

    React Server Components Flaw Lets Attackers Freeze Next.js Servers With a Single POST Request Details: https://cybersecuritynews.com/react-server-components-dos-vulnerability/ A high-severity denial-of-service flaw (CVE-2026-23870) in React Server Components can allow a remote attacker to freeze vulnerable Next.js servers by sending a specially crafted POST request to a Server Function endpoint. The vulnerability stems from the way React rebuilds submitted form data before a Server Action runs. An attacker does not need to break into the application or access protected data. Instead, they can force the server to run many repeated checks, consume CPU resources, and stop it from responding to normal visitors. React fixed the flaw in versions 19.0.6, 19.1.7, and 19.2.6. #cybersecuritynews

    0301001.5K
    75.4K followersView on X
  • Huda Al-Assaf@0x0Huda
    PoC

    Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) https://github.com/dwisiswant0/next-16.2.4-pocs

    Post summary

    The author shares a GitHub repository containing Proof‑of‑Concept code for several Next.js CVEs, but no active exploitation or patch information is discussed.

    020543.0K
    727 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Protect your app from CVE-2026-23870. Learn how this high-severity React Server Components DoS flaw crashes servers and how to patch your React 19 build today. #ReactJS #WebSecurity #CVE #RSC #CyberSecurity #InfoSec #React19 #DevOps #JavaScript #WebDev https://securityonline.info/react-server-components-dos-vulnerability-cve-2026-23870/ https://t.co/TUqL65XVhC

    Post summary

    The tweet promotes a patch for the CVE‑2026‑23870 React Server Components DoS vulnerability, urging users to update React 19 to mitigate the high‑severity flaw.

    01070557
    12.5K followersView on X
  • Simon@soeckly

    One unauthenticated POST freezes any Next.js server. Reported to Meta, fixed as CVE-2026-23870, no credit and no reply. So here's the writeup: https://simonkoeck.com/writeups/react-rsc-formdata-event-loop-dos

    00040224
    3.2K followersView on X
  • InfiniStrategy@InfiniStrategy
    Disclosure

    Web security is having a brutal month. Chrome's July 1 update patched 382 vulnerabilities, including 15 critical bugs enabling remote code execution. Meanwhile, Next.js faces multiple denial-of-service vulnerabilities affecting versions 13 through 16, with CVE-2026-23870 impacting React Server Components and CVE-2026-44577 targeting the image optimization API. The Spring Framework also revealed a zero-day dubbed Spring4Shell. The scale of these findings reflects a broader reality. As web applications grow more complex, so does their attack surface. Server components, edge functions, and AI integrations have added layers that security audits struggle to keep pace with. Frameworks that prioritize developer speed over defensive defaults are creating technical debt that manifests as vulnerabilities. What stands out is how quickly exploits appear. The Next.js image optimization flaw allows attackers to fetch local images into memory without size limits, crashing self-hosted instances. The Spring4Shell discovery caused immediate confusion as researchers determined whether it was new or related to older issues. InfiniStrategy take: Web development in 2026 demands a security-first mindset, not as an afterthought but as a core engineering principle. The frameworks winning developer adoption are those baking security into their defaults, not bolting it on after exploits surface. For businesses, the lesson is clear. Choosing technology based solely on developer velocity without considering security posture creates liability that compounds over time. The most sustainable web applications are built with defensive architecture from day one, because in today's threat landscape, security is not a feature, it is a foundation. Sources: https://cybersecuritynews.com/chrome-update-fixes-382-vulnerabilities/ https://advisories.gitlab.com/npm/next/GHSA-8h8q-6873-q5fj/ https://www.darkreading.com/application-security/zero-day-vulnerability-discovered-in-java-spring-framework

    Post summary

    The text announces the discovery of several new web‑application vulnerabilities—including critical Chrome bugs, Next.js denial‑of‑service flaws, and the Spring4Shell zero‑day—highlighting the rapid pace of vulnerability disclosure in the industry.

    01010233
    10 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23870 A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-o… https://www.cve.org/CVERecord?id=CVE-2026-23870

    Post summary

    The text announces CVE‑2026‑23870 as a denial‑of‑service flaw triggered by crafted HTTP requests to server function endpoints, but offers no PoC, exploit code, active exploitation evidence, or patch details.

    00020164
    57.7K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    On May 10, 2026, security researchers disclosed CVE-2026-23870, a critical-to-high severity vulnerability affecting React Server Components (RSC) and its dependent frameworks, most notably Next.js App Router. The flaw resides in how the React Flight protocol—the…

    Post summary

    Security researchers disclosed a critical‑to‑high severity vulnerability (CVE-2026-23870) affecting React Server Components and Next.js App Router due to an issue in the React Flight protocol.

    1000044
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    The Recursive Trap: CVE-2026-23870 Turns React Server Components Into a DoS Weapon. The Recursive Trap: How CVE-2026-23870 Weaponizes React Server Components

    Post summary

    The headline indicates that CVE-2026-23870 could enable DoS attacks against React Server Components, but it does not provide any PoC, exploit, patch information, or detailed technical analysis beyond the high-level claim.

    1000035
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    TL;DR A high-severity denial-of-service vulnerability (CVE-2026-23870) in React Server Components allows unauthenticated attackers to trigger CPU exhaustion on Next.js and React-based applications. Crafted HTTP payloads exploiting the React Flight deserialization protocol…

    Post summary

    The post discloses a high‑severity denial‑of‑service vulnerability (CVE‑2026‑23870) that lets unauthenticated attackers trigger CPU exhaustion on Next.js and React applications via crafted HTTP payloads exploiting the React Flight deserialization protocol. No proof‑of‑concept, exploit code, mitigation, or active exploitation reports are included.

    1000038
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    1. Low-effort, high-impact DoS: Unlike volumetric DDoS attacks that require botnets or high bandwidth, CVE-2026-23870 allows a single attacker (or small team) to exhaust a server's computational resources with minimal traffic. A few kilobytes per second can knock a…

    Post summary

    The text announces CVE‑2026‑23870 as a low‑effort, high‑impact DoS vulnerability that allows a single attacker to exhaust a server’s resources with minimal traffic, with no evidence of active exploitation, patch, or PoC.

    1000039
    294 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Next.js に 5 件の深刻な脆弱性が FIX:DoS/SSRF/認証バイパスに対応 https://iototsecnews.jp/2026/05/08/multiple-critical-flaws-fixed-in-next-js-and-react-server-components/ 今回の脆弱性の主な原因は、リクエストの処理過程における検証不足や予期しない挙動にあります。たとえば CVE-2026-44575/CVE-2026-44574/CVE-2026-44573 では、特定の URL やパラメータを細工することで、ミドルウェアによる認証チェックが回避されてしまいます。 また、CVE-2026-23870/CVE-2026-44579 は、データの復元処理やリクエスト処理の不備が CPU の過負荷やデッドロックを引き起こし、サービス停止を招くものです。 さらに CVE-2026-44578 では WebSocket の仕組みを悪用した不正な通信の中継が問題となりました。ご利用のチームは、ご注意ください。 #CVE202623870 #CVE202644573 #CVE202644574 #CVE202644575 #CVE202644579 #Nextjs #Vulnerability

    Post summary

    The post announces five critical Next.js vulnerabilities—authentication bypass, DoS, SSRF, and WebSocket misuse—without detailing exploits, patch steps, or active attacks, primarily serving as a disclosure of the flaws.

    01000184
    489 followersView on X
  • Hacking Team@HackingTeam77
    PoC

    next-16.2.4-pocs Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-445... https://github.com/dwisiswant0/next-16.2.4-pocs #exploit

    Post summary

    A GitHub repository hosts Proof‑of‑Concept exploit code for several New Next.js CVEs, but no active exploitation, patches, or technical details are mentioned.

    01000342
    1.6K followersView on X
  • Cyber Edition@CyberEdition
    Patch

    ⚠️ Next.js pushed an urgent May 2026 security update fixing 13 flaws, including auth bypass, SSRF, cache poisoning, XSS, and a React Server Components DoS bug (CVE-2026-23870). Update to Next.js 15.5.18 / 16.2.6 ASAP. Source: https://vercel.com/changelog/next-js-may-2026-security-release #NextJS #CyberSecurity

    Post summary

    The post announces that Next.js issued a May‑2026 security update (v15.5.18 / v16.2.6) to patch 13 vulnerabilities, including auth bypass, SSRF, cache poisoning, XSS, and a DoS bug, and urges immediate upgrade.

    00010188
    728 followersView on X
  • SOVEREIGN@munreader
    Patch

    🚨 #SovereignSignal CRITICAL SECURITY ALERT FOR DEV COMMUNITY! 🚨 Multiple high-severity vulnerabilities (May 6, 2026) disclosed affecting React 19 Server Components & @nextjs 15/16. ⚠️ Vulnerabilities: • CVE-2026-23870: RSC Denial of Service • GHSA-267c-6grr-h53f: Middleware Bypass • GHSA-c4j6-fc7j-m34r: WebSocket SSRF 🛠️ HOW TO FIX IMMEDIATELY: Upgrade your apps now to patched versions: 👉 Next.js: 15.5.16 or 16.2.5+ 👉 React: 19.0.6, 19.1.7, or 19.2.6+ Special thanks to the security teams at @CloudflareDev & @vercel_dev for swift coordination of WAF rule deployments! Protect your systems, family. 🦋🔒 #webdev #javascript #nextjs #reactjs #cybersecurity #infosec #programming #coding #100DaysOfCode

    Post summary

    The post announces critical vulnerabilities in React and Next.js and provides immediate upgrade paths to patched releases, while describing the nature of each flaw.

    00010231
    112 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appfacebookreact-server-dom-parcel-node.js-
Appfacebookreact-server-dom-turbopack-node.js-
Appfacebookreact-server-dom-webpack-node.js-

Explore more