Resource exhaustion in React - CVE-2026-23864
Published: January 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can send a specially crafted HTTP request to the application, trigger resource exhaustion and perform a denial of service (DoS) attack.
The vulnerability affects the following components:
Affected software
Next.js
How to mitigate CVE-2026-23864
Next.js - addressed in versions 15.0.8, 15.1.12, 15.2.9, 15.3.9, 15.4.11, 15.5.10, 16.0.11, 16.1.5