highCVSS 7.5Vulnerability
GHSA-8h8q-6873-q5fj
A vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23870](https://github.com/facebook/react/security/advisories/GHSA-rv78-f8rc-xrxh). A specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage. This can result in denial of service in unpatched environments.
Properties
- ghsa_id
- GHSA-8h8q-6873-q5fj
- summary
- Next.js Vulnerable to Denial of Service with Server Components
- severity
- high
- cvss_score
- 7.5
- cve_id
- GHSA-8h8q-6873-q5fj
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- is_ghsa_only
- true
- ghsa_published
- 2026-05-11T14:50:27Z
- source_url
- https://github.com/advisories/GHSA-8h8q-6873-q5fj
- ghsa_updated
- 2026-05-11T14:50:28Z
Related Entities (4)
AFFECTS (1)
→[Software]npm/next
HAS_WEAKNESS (1)
→[Weakness]Allocation of Resources Without Limits or Throttling
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]npm/next
Explore deeper with Ninja Signal's threat intelligence graph