Executive brief
A vulnerability in the React Server Components used by Next.js and other web frameworks can allow an attacker to crash a website or make it unresponsive. By sending a specially crafted request to the server, an attacker can force the system to consume excessive processor power or memory. This results in a denial of service, preventing legitimate users from accessing the application.
Technical details
A denial of service vulnerability exists in React Server Components (RSC) packages (webpack, parcel, and turbopack variants) and frameworks that implement them, such as Next.js. The root cause is a failure to properly limit resource allocation during the deserialization of RSC data sent to Server Function endpoints (CWE-770, CWE-400). A remote, unauthenticated attacker can send a specially crafted HTTP request to any App Router Server Function endpoint to trigger excessive CPU usage or out-of-memory (OOM) exceptions. This vulnerability is tracked upstream as CVE-2026-23870. Patches are available in Next.js versions 15.5.16 and 16.2.5, and React versions 19.0.6, 19.1.7, and 19.2.6.
Affected products
- Vercel Next.js >= 13.0.0, < 15.5.16; >= 16.0.0, < 16.2.5
- Facebook React Server Components (react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack) 19.0.0 - 19.0.5, 19.1.0 - 19.1.6, 19.2.0 - 19.2.5
- Vite @vitejs/plugin-rsc <= 0.5.25
Timeline
- 2026-05-06: disclosed: Initial advisory publication by Vercel and Facebook
- 2026-05-06: patched: Fixes released for Next.js and React packages
- 2026-05-11: advisory: GitHub Advisory Database entry reviewed and updated
References
- https://github.com/facebook/react/security/advisories/GHSA-rv78-f8rc-xrxh
- https://github.com/vercel/next.js/security/advisories/GHSA-8h8q-6873-q5fj
- https://github.com/vitejs/vite-plugin-react/security/advisories/GHSA-w94c-4vhp-22gx
- https://api.github.com/repos/vercel/next.js/security-advisories/GHSA-8h8q-6873-q5fj