github.com
https://github.com/facebook/react/security/advisories/GHSA-rv78-f8rc-xrxh GHSA-8H8Q-6873-Q5FJ
Next.js Vulnerable to Denial of Service with Server Components
Description
A vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23870](https://github.com/facebook/react/security/advisories/GHSA-rv78-f8rc-xrxh). A specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage. This can result in denial of service in unpatched environments.
Description source: GitHub Advisory
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| GitHub Advisory | 13.0.0 to < 15.5.16 · Fixed in 15.5.16 | affected | |
| 16.0.0 to < 16.2.5 · Fixed in 16.2.5 | affected |
References
5github.com
https://github.com/vercel/next.js github.com
https://github.com/vercel/next.js/security/advisories/GHSA-8h8q-6873-q5fj github.com
https://github.com/vitejs/vite-plugin-react/security/advisories/GHSA-w94c-4vhp-22gx nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-23870