Executive brief
Next.js is a popular web development framework used to build fast, high-performance websites. A vulnerability in its Server Components handling allows an attacker to crash a website or make it unresponsive by sending a specially crafted request. This could lead to a service outage, preventing customers from accessing the site and impacting business operations.
Technical details
A Denial of Service vulnerability exists in Next.js due to improper resource management (CWE-770) during the deserialization of React Server Components. The flaw is located in the App Router's Server Function endpoints. A remote, unauthenticated attacker can send a specially crafted HTTP request that, when processed by the server, triggers excessive CPU consumption. This leads to resource exhaustion and a denial-of-service condition. The issue is an upstream vulnerability in React Server Components (CVE-2026-23869) affecting Next.js versions 13 through 16. Patches are available in versions 15.5.15 and 16.2.3.
Affected products
- Vercel Next.js >= 13.0.0, < 15.5.15; >= 16.0.0-beta.0, < 16.2.3
Timeline
- 2026-04-08: disclosed: Advisory published by Vercel/Next.js team
- 2026-04-10: advisory: GitHub Advisory Database entry reviewed