Junglewise Threat Intelligence

Vercel Next.js denial of service in Server Components

Severity: high · CVSS 7.5 · Published 2026-04-10

Technologies: Vercel Next.js. Vendors: Vercel.

Executive brief

Next.js is a popular web development framework used to build fast, high-performance websites. A vulnerability in its Server Components handling allows an attacker to crash a website or make it unresponsive by sending a specially crafted request. This could lead to a service outage, preventing customers from accessing the site and impacting business operations.

Technical details

A Denial of Service vulnerability exists in Next.js due to improper resource management (CWE-770) during the deserialization of React Server Components. The flaw is located in the App Router's Server Function endpoints. A remote, unauthenticated attacker can send a specially crafted HTTP request that, when processed by the server, triggers excessive CPU consumption. This leads to resource exhaustion and a denial-of-service condition. The issue is an upstream vulnerability in React Server Components (CVE-2026-23869) affecting Next.js versions 13 through 16. Patches are available in versions 15.5.15 and 16.2.3.

Affected products

  • Vercel Next.js >= 13.0.0, < 15.5.15; >= 16.0.0-beta.0, < 16.2.3

Timeline

  • 2026-04-08: disclosed: Advisory published by Vercel/Next.js team
  • 2026-04-10: advisory: GitHub Advisory Database entry reviewed

References

Related threats