React Server Components DoS vulnerability disclosed; Next.js 13–14 reach EOL without patch
A denial-of-service (DoS) vulnerability (CVE-2026-23869, CVSS 7.5) has been disclosed affecting React Server Components (RSCs), a feature used by Next.js and other React metaframeworks. A malicious payload can cause excessive CPU consumption. Here's what Netlify customers need to know. Impact on Netlify Nominally, this is a server-side DoS vulnerability. However, on Netlify this has minimal impact: our autoscaling serverless architecture means that a malicious request resulting in a crashed or hung function does not affect other requests. However, active exploitation could increase your function costs. Affected frameworks All RSC frameworks are affected:
- Next.js (see version table below)
- React Router 7 (if using RSC preview)
- Waku
- @parcel/rsc
- @vitejs/plugin-rsc
Astro, Gatsby, and Remix are not affected. React affected versions See the React advisory for full details. Affected versions: 19.0.0–19.0.4 Fixed in: 19.0.5 Affected versions: 19.1.0–19.1.5 Fixed in: 19.1.6 Affected versions: 19.2.0–19.2.4 Fixed in: 19.2.5 Next.js affected versions See the Next.js advisory for full details. Affected versions: 13.3.0+ Fixed in: EOL - no fix Affected versions: 14.x Fixed in: EOL - no fix Affected versions: 15.0.0–15.5.14 Fixed in: 15.5.15 Affected versions: 16.0.0–16.2.2 Fixed in: 16.2.3 What should I do? If any of your projects are using an affected version, we recommend upgrading as soon as possible to a patched release. For Next.js 13.x and 14.x users: patches are not planned for these versions. Consider upgrading to Next.js 15.x or 16.x. Note that any publicly available deploy previews and branch deploys may remain vulnerable until they are automatically deleted. Consider deleting these deploys manually. Resources
- React CVE-2026-23869
- React security advisory
- Next.js security advisory
Fetched August 11, 2026