React Server Components Flaw Lets Attackers Freeze Next.js Servers With a Single POST Request
A high-severity denial-of-service flaw, CVE-2026-23870, in React Server Components lets a remote attacker freeze vulnerable Next.js servers with a single specially crafted POST request, CyberSecurity News reports. The finding underscores the exposure hiding in widely used web frameworks.