React Server Components Flaw Lets Attackers Freeze Next.js Servers With a Single POST Request
A high-severity denial-of-service flaw (CVE-2026-23870) in React Server Components can allow a remote attacker to freeze vulnerable Next.js servers by sending a specially crafted POST request to a Server Function endpoint. The issue has a CVSS score of 7.5 and affects React Server Components...