CVE-2026-23864
Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack.
The vulnerabilities are triggered by sending specially crafted HTTP requests to Server Function endpoints, and could lead to server crashes, out-of-memory exceptions or excessive CPU usage; depending on the vulnerable code path being exercised, the application configuration and application code.
Strongly consider upgrading to the latest package versions to reduce risk and prevent availability issues in applications using React Server Components.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.58%
- Percentil entre todas las CVEs puntuadas: 85
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access92 % - Impacto principal
T1499.004Application or System Exploitationimpact85 % - Impacto secundario
T1499.001OS Exhaustion Floodimpact78 %
AV:N, PR:N, UI:N indica explotación remota sin autenticación (T1190). Peticiones HTTP especiales causan crashes, OOM y CPU exhausto (DoS, T1499.004 y T1499.001).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-400, CWE-502
- CWE-1284
Referencias
- https://www.facebook.com/security/advisories/cve-2026-23864
- https://access.redhat.com/errata/RHSA-2026:13571
- https://access.redhat.com/errata/RHSA-2026:34608
- https://access.redhat.com/security/cve/CVE-2026-23864
- https://bugzilla.redhat.com/show_bug.cgi?id=2433059
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23864.json
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-23864",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-23864",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-01-26T20:26:03.428817Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
},
{
"type": "Secondary",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve-assign@fb.com",
"affectedData": [
{
"vendor": "Meta",
"product": "react-server-dom-webpack",
"versions": [
{
"status": "affected",
"version": "19.0.0",
"lessThan": "19.0.4",
"versionType": "semver"
},
{
"status": "affected",
"version": "19.1.0",
"lessThan": "19.1.5",
"versionType": "semver"
},
{
"status": "affected",
"version": "19.2.0",
"lessThan": "19.2.4",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Meta",
"product": "react-server-dom-turbopack",
"versions": [
{
"status": "affected",
"version": "19.0.0",
"lessThan": "19.0.4",
"versionType": "semver"
},
{
"status": "affected",
"version": "19.1.0",
"lessThan": "19.1.5",
"versionType": "semver"
},
{
"status": "affected",
"version": "19.2.0",
"lessThan": "19.2.4",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Meta",
"product": "react-server-dom-parcel",
"versions": [
{
"status": "affected",
"version": "19.0.0",
"lessThan": "19.0.4",
"versionType": "semver"
},
{
"status": "affected",
"version": "19.1.0",
"lessThan": "19.1.5",
"versionType": "semver"
},
{
"status": "affected",
"version": "19.2.0",
"lessThan": "19.2.4",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"affectedData": [
{
"cpes": [
"cpe:/a:redhat:amq_streams:2.9::el9"
],
"vendor": "Red Hat",
"product": "Streams for Apache Kafka 2.9.4",
"packageName": "com.github.streamshub-console",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:amq_streams:3.2::el9"
],
"vendor": "Red Hat",
"product": "Streams for Apache Kafka 3.2.0",
"packageName": "com.github.streamshub-console",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-01-26T20:16:16.773",
"references": [
{
"url": "https://www.facebook.com/security/advisories/cve-2026-23864",
"tags": [
"Vendor Advisory"
],
"source": "cve-assign@fb.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:13571",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:34608",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2026-23864",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2433059",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23864.json",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-400"
},
{
"lang": "en",
"value": "CWE-502"
}
]
},
{
"type": "Secondary",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"description": [
{
"lang": "en",
"value": "CWE-1284"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack.\n\nThe vulnerabilities are triggered by sending specially crafted HTTP requests to Server Function endpoints, and could lead to server crashes, out-of-memory exceptions or excessive CPU usage; depending on the vulnerable code path being exercised, the application configuration and application code.\n\nStrongly consider upgrading to the latest package versions to reduce risk and prevent availability issues in applications using React Server Components."
},
{
"lang": "es",
"value": "Múltiples vulnerabilidades de denegación de servicio existen en los Componentes de Servidor de React, afectando los siguientes paquetes: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack.\n\nLas vulnerabilidades se activan al enviar solicitudes HTTP especialmente diseñadas a los puntos finales de las Funciones de Servidor, y podrían provocar caídas del servidor, excepciones por falta de memoria o uso excesivo de CPU; dependiendo de la ruta de código vulnerable que se esté ejecutando, la configuración de la aplicación y el código de la aplicación.\n\nConsidere encarecidamente actualizar a las últimas versiones de los paquetes para reducir el riesgo y prevenir problemas de disponibilidad en aplicaciones que utilizan Componentes de Servidor de React."
}
],
"lastModified": "2026-07-15T02:18:44.527",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:facebook:react:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0F93D6DB-994E-428D-970C-D50737B628CF",
"versionEndExcluding": "19.0.4",
"versionStartIncluding": "19.0.0"
},
{
"criteria": "cpe:2.3:a:facebook:react:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2151CF1A-4E87-421E-9714-3AA87639FD6B",
"versionEndExcluding": "19.1.5",
"versionStartIncluding": "19.1.0"
},
{
"criteria": "cpe:2.3:a:facebook:react:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9FC73AD9-7EA4-4789-B75B-DC1FFF6F66AF",
"versionEndExcluding": "19.2.4",
"versionStartIncluding": "19.2.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve-assign@fb.com"
}