Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. react-server-dom-turbopack
  4. ›
  5. CVE-2026-23869

CVE-2026-23869: React Server Components have a Denial of Service Vulnerability

April 10, 2026

A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack versions 19.0.0, 19.1.0 and 19.2.0. The vulnerability is triggered by sending specially crafted HTTP requests to Server Function endpoints.

The payload of the HTTP request causes excessive CPU usage for up to a minute ending in a thrown error that is catchable.

We recommend updating immediately.

The vulnerability exists in versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4 of:

react-server-dom-webpack react-server-dom-parcel react-server-dom-turbopack

References

  • github.com/advisories/GHSA-479c-33wc-g2pg
  • github.com/facebook/react
  • github.com/facebook/react/security/advisories/GHSA-479c-33wc-g2pg
  • nvd.nist.gov/vuln/detail/CVE-2026-23869
  • react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components

Code Behaviors & Features

Detect and mitigate CVE-2026-23869 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 19.0.0 before 19.0.5, all versions starting from 19.1.0 before 19.1.6, all versions starting from 19.2.0 before 19.2.5

Fixed versions

  • 19.0.5
  • 19.1.6
  • 19.2.5

Solution

Upgrade to versions 19.0.5, 19.1.6, 19.2.5 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-400: Uncontrolled Resource Consumption
  • CWE-502: Deserialization of Untrusted Data

Source file

npm/react-server-dom-turbopack/CVE-2026-23869.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 09 May 2026 12:20:08 +0000.