A significant vulnerability identified as CVE-2026-23870 in React Server Components poses a serious threat to Next.js servers. This denial-of-service flaw can be exploited by remote attackers who send a crafted POST request to a Server Function endpoint, potentially freezing the server. The flaw, with a CVSS score of 7.5, affects React 19.x applications, particularly those using Server Actions in Next.js environments.
Root Cause and Exploitation
The vulnerability arises from React’s method of processing form data before executing Server Actions. Attackers can exploit this by causing repetitive checks that consume CPU resources, ultimately preventing the server from responding to legitimate users. The flaw is inherent in the way React rebuilds form data, specifically in handling $K references within submitted fields, leading to extensive and costly comparisons.
For instance, a POST request containing 10,000 references and form fields can result in approximately 100 million string comparisons, significantly burdening the server. This issue, demonstrated by researcher Simon Koeck, can be triggered with requests as small as 900 KB, emphasizing the processing rather than the size as the vulnerability’s concern.
Impact on Next.js Deployments
Next.js implementations, particularly those running on Node.js, are vulnerable due to CPU-intensive synchronous processing that can block the event loop. As the server processes attacker-controlled form fields, it may fail to handle other incoming requests, resulting in slow responses or HTTP 503 errors for legitimate users. Such incidents could cause applications to be marked unhealthy, leading to their removal from service.
This vulnerability is critical as it affects the request parsing phase, preceding any Server Action logic, making it difficult for existing security measures to mitigate the risk. Publicly accessible Server Actions are particularly at risk, although authenticated applications are not immune if accessible endpoints are compromised.
Mitigation Measures and Recommendations
React has addressed this flaw in versions 19.0.6, 19.1.7, and 19.2.6. Organizations must upgrade to these versions promptly to secure their systems. Developers should verify dependencies to ensure no vulnerable React server-dom packages are included. The update involves a change in the form-data processing path, reducing repeated scans and CPU load.
Aside from upgrading, teams should implement edge and reverse-proxy controls, such as POST body-size limits and request-rate controls, to mitigate potential attacks. Yet, patching the React framework remains crucial due to the underlying issue in its request-processing logic.
Administrators should also watch for abnormal POST activity on pages with Server Actions, which might indicate an attack. Monitoring for spikes in CPU usage, request queues, and health-check failures can help identify and respond to potential threats swiftly.
By addressing this vulnerability through timely updates and robust security measures, organizations can protect their Next.js deployments from potential denial-of-service attacks.
