FixVibe

high

Denial of Service in React Server Components (CVE-2026-23864)

Multiple denial of service (DoS) vulnerabilities exist in React Server Components, specifically affecting the react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack packages. Attackers can trigger these vulnerabilities by sending specially crafted HTTP requests to Server Functions, potentially exhausting server resources or crashing the application process.

CVE-2026-23864GHSA-83fc-fqcc-2hmgCVE-2026-23864CWE-400CWE-502CWE-1284

Impact

Applications using affected React Server Components (RSC) Server Function transports can face denial-of-service risk when vulnerable React Server DOM packages handle specially crafted HTTP requests [S1][S2]. The impact is availability-focused: affected runtimes may consume excessive CPU or memory or terminate unexpectedly, depending on the deployed framework, code path, and hosting environment [S1][S2].

Root Cause

CVE-2026-23864 affects React Server DOM packages used by RSC transports, including the Webpack, Parcel, and Turbopack integrations [S1][S2]. Advisory sources describe vulnerable request handling around Server Functions; the React project and advisory databases identify patched React Server DOM release lines for affected 19.x versions [S1][S2][S3]. Frameworks that embed those packages, including Next.js App Router deployments, may need a framework update so the patched dependency is installed in the final application graph [S4].

How FixVibe covers it

FixVibe's GitHub repo scans flag affected react-server-dom-webpack, react-server-dom-turbopack and react-server-dom-parcel versions, with the file, version, affected range and fixed version so you can patch the dependency path.

Fixes

Upgrade the affected React Server DOM package, or the framework release that pins it, so the installed dependency resolves to the patched release for the active React line [S1][S2][S4]. Regenerate the active npm, pnpm, or Yarn lockfile, rebuild deployment artifacts and dependency caches, and rerun the FixVibe GitHub repo scan. Normal request-size, concurrency, and rate-limit controls remain useful defense in depth during rollout, but they do not replace the dependency upgrade [S2].