A critical security vulnerability has been uncovered in the deployments of React Server Components, specifically affecting certain releases of React 19. This flaw poses a serious threat, as attackers can take advantage of it to induce a denial-of-service (DoS) condition using specially crafted HTTP POST requests. The vulnerability is documented under CVE-2026-23870.
The Nature of the Vulnerability
Identified and tracked as CVE-2026-23870 and GHSA-rv78-f8rc-xrxh, the high-severity vulnerability has garnered particular attention due to its impact on React Server Components packages widely utilized across various frameworks, prominently including Next.js. Meta, the parent company of React, has assigned the flaw a CVSS score of 7.5. One of the alarming aspects of this vulnerability is that it can be exploited over a network with minimal complexity. Notably, it does not require any user privileges or interaction, making it an easier target for malicious actors.
The underlying issue arises from how React manages Server Actions— a feature that facilitates server-side function invocation during form submissions. When a Server Action is triggered, React reconstructs the submitted multipart form data from the raw HTTP request. This process, while seemingly straightforward, employs a specific reference type known as $K, which points React towards resolving an embedded or nested form data structure.
In this context, for every $K reference encountered, the affected code is designed to create a comprehensive list of all the submitted form fields. This list is subsequently iterated over to find matching fields. However, this method results in an inefficient, quadratic processing model: a request containing n crafted references and n form fields can lead to around n² string comparisons. For example, a request tagged with 10,000 $K references and an equal number of filler fields can balloon to approximately 100 million checks, necessitating a payload size of around 900 KB.
The Consequences of Exploitation
Node.js, which typically handles JavaScript request processing on a single event-loop thread, can be severely impacted by this excessive CPU workload. Such workload spikes can block other incoming requests, resulting in significant delays or complete failures of pages, APIs, and further Server Action callbacks until the parsing concludes.
Critical to note is that the vulnerability’s deserialization process occurs prior to any application-level authorization checks for the Server Action. This timing allows attackers to exploit the vulnerability without needing to authenticate, provided that the endpoint to the affected Server Action is publicly accessible. Although some degree of knowledge regarding the Server Action identifier is necessary for the attack, these identifiers often appear in rendered HTML or JavaScript assets dispatched to a browser. This means public-facing pages that include simple Server Actions may unwittingly provide a plausible attack vector for exploitation.
Categorized under CWE-400, or uncontrolled resource consumption, the ramifications of this vulnerability are dire. According to records from the National Institute of Standards and Technology (NIST), malicious HTTP requests can lead to excessive CPU usage, out-of-memory conditions, or catastrophic server crashes.
Affected Frameworks and Packages
The vulnerable packages include:
react-server-dom-webpackreact-server-dom-turbopackreact-server-dom-parcel
The impacted versions are:
- React 19.0.0 through 19.0.5
- React 19.1.0 through 19.1.6
- React 19.2.0 through 19.2.5
Organizations utilizing Next.js applications with React Server Components and Server Actions should not rely solely on request-size limitations, existing authentication measures, CSRF protections, or rate limits to safeguard against this vulnerability. This caution is warranted as the costly parsing operations occur before any actual checks can be made against the action level, making them susceptible to triggering via comparatively small requests.
Mitigation Steps
To rectify the identified vulnerability, Meta has rolled out patch updates in React versions 19.0.6, 19.1.7, and 19.2.6. These updates alter the parsing strategy, processing fields through shared traversal as opposed to initiating full scans for each nested $K reference. This adjustment effectively eradicates the repeated scanning process that results in CPU spikes.
In view of this serious security risk, development teams are urged to promptly audit their lock files and production builds. They should upgrade React Server Components dependencies to the patched versions, followed by the necessary application rebuilds and redeployments.
Moreover, security teams are advised to keep a vigilant watch for any unusual multipart POST activity targeting routes hosting Server Actions. Specific attention should be directed toward detecting abrupt bursts of requests that involve an atypically high number of form fields or nested serialized references. By adopting these proactive measures, organizations can better safeguard themselves against this and similar vulnerabilities in the future.
In conclusion, the implications of the identified vulnerability underscore the importance for organizations to remain vigilant, implementing timely updates and protections to mitigate potential cyber threats that can significantly disrupt service continuity.
