← Vulnerability feed

Vulnerability record · CVE-2026-23864 · published 26 January 2026

CVE-2026-23864: Facebook react uncontrolled resource consumption vulnerability

Facebook · React

Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending specially crafted HTTP requests to Server Function endpoints, and could lead to server crashes, out-of-memory exceptions or excessive CPU usage; depending on the vulnerable code path being exercised, the application configuration and application code. Strongly consider upgrading to the latest package versions to reduce risk and prevent availability issues in applications using React Server Components.

7.5 CVSS 3.1 High EPSS 2.6% · top 15.4% CWE-400 · Uncontrolled resource consumptionCWE-502 · Deserialization of untrusted data
7.5CVSS 3.1 base score
2.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
15 Jul 2026Last modified by NVD

Description

Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending specially crafted HTTP requests to Server Function endpoints, and could lead to server crashes, out-of-memory exceptions or excessive CPU usage; depending on the vulnerable code path being exercised, the application configuration and application code. Strongly consider upgrading to the latest package versions to reduce risk and prevent availability issues in applications using React Server Components.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-23864 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-55182React Server Components pre-auth deserialization RCEReact Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 (react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack) u…KEVEPSS 100%analysed7.5CVE-2025-67779Facebook react deserialization of untrusted data vulnerabilityIt was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a sp…EPSS 20%7.5CVE-2025-55184React Server Components pre-auth deserialization denial of serviceReact Server Components versions 19.0.0 through 19.2.1 (react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack) unsafely deser…EPSS 67%analysed6.1CVE-2018-6341Facebook react cross-site scripting vulnerabilityReact applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of e…EPSS 3.4%5.3CVE-2025-55183React Server Components source code leak via crafted HTTP requestReact Server Components versions 19.0.0 through 19.2.1 (react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack) can return the…EPSS 64%analysed7.5CVE-2026-28318SolarWinds Serv-U unauthenticated POST request denial of serviceSolarWinds Serv-U crashes when it receives a specially crafted POST request using Content-Encoding: deflate, and the crash occurs without authenticat…KEVEPSS 1.9%analysed7.5CVE-2026-45498Microsoft Defender antimalware platform uncontrolled resource consumption DoSCVE-2026-45498 is a denial of service flaw in the Microsoft Defender antimalware platform, classified as uncontrolled resource consumption (CWE-400).…KEVEPSS 1.3%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2026-23864), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.