A security vulnerability has been identified in React Server Components deployments using specific vulnerable releases of React 19.
An attacker can exploit this flaw to create a denial-of-service condition through specially crafted HTTP POST requests, as detailed in CVE-2026-23870.
React Server Components Vulnerability
Tracked as CVE-2026-23870 and GHSA-rv78-f8rc-xrxh, this high-severity vulnerability affects React Server Components packages utilized by frameworks such as Next.js.
Meta has assigned this flaw a CVSS score of 7.5. An attacker can exploit the vulnerability over a network with low attack complexity, requiring no privileges or user interaction, and it on significantly impact availability.
The vulnerability arises from React’s management of Server Actions. This feature allows for server-side function invocation during form submissions. Before executing the action, React reconstructs the submitted multipart form data from the raw HTTP request.
According to researcher Simonkoeck, an attacker can exploit a $K reference type, which directs React to resolve an embedded or nested form data structure.
For each $K reference, the affected code creates a complete list of all the submitted form fields and iterates over this full list to locate matching fields.
This process results in quadratic processing: a request with n crafted references and n form fields can lead to approximately n² string comparisons.
For instance, a request containing 10,000 $K references and 10,000 filler fields can generate around 100 million checks from a request about 900 KB in size.
Since Node.js typically handles JavaScript request processing on a single event-loop thread, this excessive CPU workload can block other requests, causing pages, APIs, and additional Server Action calls to stall or time out until the parsing is complete.
The vulnerable deserialization process takes place before the application-level authorization checks for the Server Action are executed. This means that an attacker may not need to authenticate if an affected Server Action endpoint is accessible from a public page.
While an attacker needs a Server Action identifier, these identifiers often appear in rendered HTML or JavaScript assets sent to a client’s browser. Consequently, any public-facing page that includes simple Server Actions may provide enough of an attack surface for exploitation.
This issue is categorized as CWE-400, which refers to uncontrolled resource consumption. According to NIST’s vulnerability record, malicious HTTP requests could cause excessive CPU usage, out-of-memory conditions, or server crashes.
Affected Packages
The vulnerable packages include:
- react-server-dom-webpack
- react-server-dom-turbopack
- react-server-dom-parcel
The affected versions are React 19.0.0 through 19.0.5, React 19.1.0 through 19.1.6, and React 19.2.0 through 19.2.5.
Organizations using Next.js applications with React Server Components and Server Actions, especially those running on vulnerable React 19 dependencies, should not solely rely on request-size limits, authentication, CSRF protections, or rate limits. The costly parsing occurs before any action-level checks and can be triggered by relatively small requests.
To address the vulnerability, Meta has issued patch updates in React versions 19.0.6, 19.1.7, and 19.2.6. The fix changes the parsing approach so fields are processed through a shared traversal instead of restarting a full scan for each nested $K reference, eliminating repeated scanning that causes CPU spikes.
Teams should promptly audit their lockfiles and production builds, upgrade React Server Components dependencies to the fixed versions, rebuild applications, and redeploy.
Additionally, security teams should monitor for unusual multipart POST activity against routes that host Server Actions, looking specifically for bursts of requests with an unusual number of form fields or nested serialized references.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

