CVE detail
CVE-2026-23864
Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending specially crafted HTTP requests to Server Function endpoints, and could lead to server crashes, out-of-memory exceptions or excessive CPU usage; depending on the vulnerable code path being exercised, the application configuration and application code. Strongly consider upgrading to the latest package versions to reduce risk and prevent availability issues in applications using React Server Components.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 23.0 · diversity 18.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
9 source links · newest first
- Summary of CVE-2026-23864Hacker News
Linked URL: https://vercel.com/changelog/summary-of-cve-2026-23864 | Posted by tamnd | 1 points | 0 comments
communitynews.ycombinator.comJan 27, 2026, 7:40 AM Linked URL: https://www.cve.org/CVERecord?id=CVE-2026-23864 | Posted by nthypes | 2 points | 1 comments
communitynews.ycombinator.comJan 27, 2026, 12:11 AMLinked URL: https://vercel.com/changelog/summary-of-cve-2026-23864 | Posted by mufeedvh | 3 points | 0 comments
communitynews.ycombinator.comJan 26, 2026, 9:11 PM- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23864.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comJan 26, 2026, 8:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2433059bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comJan 26, 2026, 8:16 PM - https://access.redhat.com/security/cve/CVE-2026-23864access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 26, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:34608access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 26, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:13571access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 26, 2026, 8:16 PM - https://www.facebook.com/security/advisories/cve-2026-23864www.facebook.com
No excerpt available.
Vendor Advisorywww.facebook.comJan 26, 2026, 8:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-67779CVSS 7.5 · High
It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Comp…
- CVE-2026-59879CVSS 8.7 · High
Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#setIn, List#updateIn, and the functional set, setIn, and up…
- CVE-2026-54092CVSS 6.5 · Medium
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, unchecked passwords maxim…
- CVE-2025-70071CVSS 5.9 · Medium
An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXParser.cpp, ParseVectorDataArray()
- CVE-2025-70069CVSS 7.5 · High
An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp and ConvertMeshMultiMaterial() method
- CVE-2026-23869CVSS 7.5 · High
A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-web…