CVE-2026-23869 is a high-severity denial-of-service vulnerability in React Server Components affecting the packages react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The issue is in the deserialization logic used by Server Function endpoints. A specially crafted HTTP request can drive the vulnerable deserialization path into excessive CPU consumption for approximately 60 seconds before terminating with a catchable thrown error. The affected versions are 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4. The flaw was described as an incomplete remediation follow-up to CVE-2026-23864.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is a real exploit/PoC set for CVE-2026-23869 ('React2DoS'), an unauthenticated remote denial-of-service issue in React Server Components Flight protocol deserialization. The repo contains four files: a Nuclei template (CVE-2026-23869.yaml), a Python PoC (poc.py), a Bash helper for extracting Next.js Server Action IDs (extract-action-ids.sh), and a README. Because the repository includes a Nuclei template, it appears framework-associated; the template is the main exploit/detection artifact, while the Python and Bash files provide standalone operational tooling. The exploit capability is CPU exhaustion, not code execution. It targets Next.js applications exposing Server Actions backed by vulnerable React Server Components. The attack flow is: identify a Next.js target, extract a valid 40-hex Server Action ID from page source or JS bundles, send a baseline POST request to '/', then send a crafted multipart/form-data POST to '/' with 'Next-Action: <id>' and a malicious Flight payload containing repeated '$Q0' self-references. This abuses Map deserialization behavior to force repeated recomputation with quadratic complexity, causing long response times and effective service unavailability. The Nuclei template performs four phases: (1) GET {{BaseURL}} to fingerprint Next.js via headers/body, (2) GET {{BaseURL}} again to regex-extract createServerReference("<40 hex>") action IDs, (3) POST / with a benign multipart body to establish baseline timing, and (4) POST / with the malicious payload and flag likely vulnerability when response duration is >= 3 seconds and status is one of 200/400/404/500. This makes the template more than passive detection; it actively probes the vulnerable code path with a reduced exploit payload. The Bash script automates action ID extraction by requesting the target root, parsing HTML and Next.js bundle paths under '/_next/static/', and checking common chunk paths. The Python PoC is a fuller operational tool with automation for recon, extraction, detection, exploitation, concurrency, timing/statistics, interrupt handling, and optional JSON reporting. Overall, the repository's purpose is to identify vulnerable Next.js/React deployments and demonstrate or induce denial of service through crafted Flight protocol requests.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prior denial of service vulnerability in React Server Components discussed as part of the patch history leading to CVE-2026-23870.
A high-severity denial-of-service vulnerability in React Server Components that allows unauthenticated remote attackers to exhaust backend server resources via crafted requests to Server Function endpoints, causing prolonged CPU spikes and degraded availability.
A denial-of-service vulnerability in React Server Components deserialization logic that allows unauthenticated remote attackers to trigger excessive CPU consumption for up to about one minute per malicious request.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.