CVE-2026-23869: (CWE-502) Deserialization of Untrusted Data, (CWE-400) Uncontrolled Resource Consumption in Meta react-server-dom-turbopack
A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4). The vulnerability is triggered by sending specially crafted HTTP requests to Server Function endpoints.The payload of the HTTP request causes excessive CPU usage for up to a minute ending in a thrown error that is catchable.
AI Analysis
Technical Summary
CVE-2026-23869 is a denial of service vulnerability in Meta's React Server Components, specifically in the react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack packages. The vulnerability arises from deserialization of untrusted data and uncontrolled resource consumption. Attackers can send specially crafted HTTP requests to Server Function endpoints, which cause excessive CPU usage lasting up to a minute and ultimately throw a catchable error. The affected versions are 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4. There is no vendor advisory indicating an official fix or patch availability at this time.
Potential Impact
The vulnerability allows an unauthenticated attacker to cause a denial of service by triggering excessive CPU consumption on the server hosting the affected React Server Components. This results in degraded service availability for up to a minute per attack attempt. There is no impact on confidentiality or integrity reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch is currently documented. Until a patch is available, consider limiting access to Server Function endpoints or implementing rate limiting to reduce the risk of denial of service. Monitor vendor advisories for updates on remediation.
CVE-2026-23869: (CWE-502) Deserialization of Untrusted Data, (CWE-400) Uncontrolled Resource Consumption in Meta react-server-dom-turbopack
Description
A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4). The vulnerability is triggered by sending specially crafted HTTP requests to Server Function endpoints.The payload of the HTTP request causes excessive CPU usage for up to a minute ending in a thrown error that is catchable.
CVSS v3.1
Score 7.5high
Affected software
pkg:npm/react-server-dom-parcelpkg:npm/react-server-dom-turbopackpkg:npm/react-server-dom-webpackRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-23869 is a denial of service vulnerability in Meta's React Server Components, specifically in the react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack packages. The vulnerability arises from deserialization of untrusted data and uncontrolled resource consumption. Attackers can send specially crafted HTTP requests to Server Function endpoints, which cause excessive CPU usage lasting up to a minute and ultimately throw a catchable error. The affected versions are 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4. There is no vendor advisory indicating an official fix or patch availability at this time.
Potential Impact
The vulnerability allows an unauthenticated attacker to cause a denial of service by triggering excessive CPU consumption on the server hosting the affected React Server Components. This results in degraded service availability for up to a minute per attack attempt. There is no impact on confidentiality or integrity reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch is currently documented. Until a patch is available, consider limiting access to Server Function endpoints or implementing rate limiting to reduce the risk of denial of service. Monitor vendor advisories for updates on remediation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Meta
- Date Reserved
- 2026-01-16T19:49:26.309Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-23869","vendor":"Red Hat"}]
Threat ID: 69d6b1991cc7ad14daa7cb97
Added to database: 04/08/2026, 19:50:49 UTC
Last enriched: 07/15/2026, 08:36:25 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 233
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.