Junglewise Threat Intelligence

Next.js and React denial of service in Server Components

Severity: high · CVSS 7.5 · Published 2026-05-11

Technologies: Vite Plugin-Rsc, Vercel Next.js, Meta React Server Components (Parcel), Meta React Server Components (Webpack), Meta React Server Components (Turbopack). Vendors: Vite, Vercel, Meta.

Executive brief

A vulnerability in the React Server Components used by Next.js and other web frameworks can allow an attacker to crash a website or make it unresponsive. By sending a specially crafted request to the server, an attacker can force the system to consume excessive processor power or memory. This results in a denial of service, preventing legitimate users from accessing the application.

Technical details

A denial of service vulnerability exists in React Server Components (RSC) packages (webpack, parcel, and turbopack variants) and frameworks that implement them, such as Next.js. The root cause is a failure to properly limit resource allocation during the deserialization of RSC data sent to Server Function endpoints (CWE-770, CWE-400). A remote, unauthenticated attacker can send a specially crafted HTTP request to any App Router Server Function endpoint to trigger excessive CPU usage or out-of-memory (OOM) exceptions. This vulnerability is tracked upstream as CVE-2026-23870. Patches are available in Next.js versions 15.5.16 and 16.2.5, and React versions 19.0.6, 19.1.7, and 19.2.6.

Affected products

  • Vercel Next.js >= 13.0.0, < 15.5.16; >= 16.0.0, < 16.2.5
  • Facebook React Server Components (react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack) 19.0.0 - 19.0.5, 19.1.0 - 19.1.6, 19.2.0 - 19.2.5
  • Vite @vitejs/plugin-rsc <= 0.5.25

Timeline

  • 2026-05-06: disclosed: Initial advisory publication by Vercel and Facebook
  • 2026-05-06: patched: Fixes released for Next.js and React packages
  • 2026-05-11: advisory: GitHub Advisory Database entry reviewed and updated

References

Related threats