Denial of Service Vulnerability in React Server Packages by Facebook
CVE-2026-23870
Key Information:
- Vendor
Meta
- Vendor
- CVE Published:
- 6 May 2026
Badges
What is CVE-2026-23870?
CVE-2026-23870 is a denial of service vulnerability found in Meta's React Server Packages, specifically affecting versions 19.0.0 through 19.2.5 of packages such as react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack. This vulnerability arises when a server processes specially crafted HTTP requests directed at its function endpoints. When triggered, the vulnerability can lead to severe operational issues, including server crashes, out-of-memory exceptions, and excessive CPU usage. Organizations utilizing these packages for building and deploying applications may face significant downtime and performance degradation should this vulnerability be exploited.
Potential impact of CVE-2026-23870
-
Service Disruption: The denial of service nature of this vulnerability can cause complete server outages, impacting the availability of services for end users, potentially leading to lost revenue and a damaged reputation.
-
Resource Exhaustion: By exploiting this vulnerability, an attacker could cause the server to consume excessive resources, resulting in out-of-memory errors or hindered performance. This can degrade the user experience and may necessitate costly remedial measures.
-
Operational Costs: Addressing the issues caused by this vulnerability, including re-engineering server settings, deploying patches, and possibly scaling up system resources to handle more traffic, can incur additional operational costs for the organization, diverting valuable resources from other projects.
Affected Version(s)
react-server-dom-parcel 19.0.0 <= 19.0.5
react-server-dom-parcel 19.1.0 <= 19.1.6
react-server-dom-parcel 19.2.0 <= 19.2.5
News Articles
References
CVSS V3.1
Timeline
- π
Vulnerability started trending
- πΎ
Exploit known to exist
- π°
First article discovered by Cybersecuritynews
Vulnerability published
Vulnerability Reserved

