Allocation of Resources Without Limits or Throttling in React - CVE-2026-23870
Published: May 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in server function endpoints when handling specially crafted HTTP requests. A remote attacker can send specially crafted HTTP requests to cause a denial of service.
This can lead to out-of-memory exceptions or excessive CPU usage.
Affected software
Next.js
How to mitigate CVE-2026-23870
Next.js - addressed in versions 15.5.16, 16.2.5