PT-2026-4812 · Unknown · React-Server-Dom-Parcel+2
Published
2025-12-03
·
Updated
2026-05-08
·
CVE-2026-23864
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
React versions 19.0.0 through 19.2.3
react-server-dom-webpack versions 19.0.0 through 19.2.3
react-server-dom-parcel versions 19.0.0 through 19.2.3
react-server-dom-turbopack versions 19.0.0 through 19.2.3
Next.js versions 13.x through 16.x
Description
Multiple denial of service vulnerabilities exist in React Server Components. These issues are triggered by sending specially crafted HTTP requests to Server Function endpoints. Exploitation can lead to server crashes, out-of-memory exceptions, or excessive CPU usage, depending on the application configuration and code. The vulnerabilities stem from how the server handles multipart/form-data requests, specifically when decoding responses with tokens like
$K<id>. The parser creates a new FormData object for each such token and fully scans the original FormData, leading to memory exhaustion with a large number of tokens. While no remote code execution is possible, the denial of service impact is significant. Cloudflare and Akamai have released WAF rules to mitigate these vulnerabilities.Recommendations
React versions 19.0.0 through 19.2.3: Upgrade to version 19.2.4 or later.
react-server-dom-webpack versions 19.0.0 through 19.2.3: Upgrade to version 19.2.4 or later.
react-server-dom-parcel versions 19.0.0 through 19.2.3: Upgrade to version 19.2.4 or later.
react-server-dom-turbopack versions 19.0.0 through 19.2.3: Upgrade to version 19.2.4 or later.
Next.js versions 13.x through 16.x: Upgrade to version 16.0.11 or later.
Fix
DoS
RCE
Resource Exhaustion
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
React-Server-Dom-Parcel
React-Server-Dom-Turbopack
React-Server-Dom-Webpack