---
id: CVE-2026-23870
title: >-
  A denial of service vulnerability could be triggered by sending specially
  crafted HTTP requests to server function endpoints, this could lead to server
  crashes, out-of-memory exceptions or excessive CPU usage; affecting the
  following pac…
summary: >-
  A denial of service vulnerability could be triggered by sending specially
  crafted HTTP requests to server function endpoints, this could lead to server
  crashes, out-of-memory exceptions or excessive CPU usage; affecting the
  following pac…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
  - CWE-770
vendor: facebook
product: react-server-dom-parcel
affected:
  - 'react-server-dom-parcel >= 19.0.0, <= 19.0.5'
  - 'react-server-dom-parcel >= 19.1.0, <= 19.1.6'
  - 'react-server-dom-parcel >= 19.2.0, <= 19.2.5'
  - 'react-server-dom-turbopack >= 19.0.0, <= 19.0.5'
  - 'react-server-dom-turbopack >= 19.1.0, <= 19.1.6'
  - 'react-server-dom-turbopack >= 19.2.0, <= 19.2.5'
  - 'react-server-dom-webpack >= 19.0.0, <= 19.0.5'
  - 'react-server-dom-webpack >= 19.1.0, <= 19.1.6'
  - 'react-server-dom-webpack >= 19.2.0, <= 19.2.5'
published: '2026-05-06'
updated: '2026-08-12'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-23870'
references:
  - url: 'https://github.com/facebook/react/security/advisories/GHSA-rv78-f8rc-xrxh'
    label: cve-assign@fb.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23870.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-23870'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2467287'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-23870'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-23870'
tags:
  - nvd
  - exploit-available
  - csaf
  - vex
  - red-hat
epss: 0.01533
epssPercentile: 0.73687
ingestedAt: '2026-08-13T13:03:06.218Z'
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/dwisiswant0/next-16.2.4-pocs'
    - 'https://github.com/emresandikci/nextjs-cve-2026-23870-checker'
  checkedAt: '2026-09-25T08:20:53.236Z'
exploitAvailable: true
---

## Overview

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.5, 19.1.0 through 19.1.6, and 19.2.0 through 19.2.5).

## Affected

- `react-server-dom-parcel >= 19.0.0, <= 19.0.5`
- `react-server-dom-parcel >= 19.1.0, <= 19.1.6`
- `react-server-dom-parcel >= 19.2.0, <= 19.2.5`
- `react-server-dom-turbopack >= 19.0.0, <= 19.0.5`
- `react-server-dom-turbopack >= 19.1.0, <= 19.1.6`
- `react-server-dom-turbopack >= 19.2.0, <= 19.2.5`
- `react-server-dom-webpack >= 19.0.0, <= 19.0.5`
- `react-server-dom-webpack >= 19.1.0, <= 19.1.6`
- `react-server-dom-webpack >= 19.2.0, <= 19.2.5`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · updated 2026-09-16 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23870.json)
