« All posts

CVE-2026-23870: One Request Can Freeze Any Next.js Server

CVE-2026-23870: an O(n²) form-parsing bug in React server actions let one unauthenticated request freeze Next.js servers for seconds.

A logic flaw in how React rebuilds form data for server actions created an unauthenticated denial-of-service bug. The code resolving $K references rescanned the entire field list for every single reference, so a request with 10,000 references and 10,000 filler fields forced the server through 100 million string comparisons in one uninterrupted pass. Because Node.js handles requests on a single thread, that computation blocked every other visitor until it finished.

Existing depth and argument-count limits failed to catch the attack because the references could be nested one level deeper than the checks looked, and none of this validation happened until after the request was already parsed — meaning no login, CSRF token, or origin check could stop it. The only requirement was the action ID, which is exposed in plain text in page HTML and bundled JavaScript. In testing, a single ~900KB request froze a production-like server for roughly 4-10 seconds, and a handful of back-to-back requests were enough to trigger load-balancer failover and 503 errors for unrelated users.

Because the vulnerable code lives in React's shared internals, it affected react-server-dom-webpack, turbopack, and parcel alike — effectively any Next.js 14+ app or other React Server Components setup with at least one reachable server action. React fixed it in versions 19.0.6, 19.1.7, and 19.2.6 by making the parser walk the field list once per request instead of once per pointer, tracked as CVE-2026-23870 and GHSA-rv78-f8rc-xrxh. The researcher also noted the fix shipped silently months after disclosure, with no bounty status update or credit.

This synthesis was produced from its source by AI; there is no human editor or manual review step. How we work