highCVSS 7.5Vulnerability
GHSA-q4gf-8mx6-v5v3
A vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23869](https://github.com/facebook/react/security/advisories/GHSA-479c-33wc-g2pg). You can read more about this advisory our [this changelog](https://vercel.com/changelog/summary-of-cve-2026-23869). A specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage. This can result in denial of service in unpatched environments.
Properties
- ghsa_id
- GHSA-q4gf-8mx6-v5v3
- summary
- Next.js has a Denial of Service with Server Components
- severity
- high
- cvss_score
- 7.5
- cve_id
- GHSA-q4gf-8mx6-v5v3
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- is_ghsa_only
- true
- ghsa_published
- 2026-04-10T15:35:47Z
- source_url
- https://github.com/advisories/GHSA-q4gf-8mx6-v5v3
- ghsa_updated
- 2026-04-10T15:35:49Z
Related Entities (4)
VULNERABLE_TO (1)
←[Software]npm/next
REPORTED_BY (1)
→[Source]GitHub Advisory Database
AFFECTS (1)
→[Software]npm/next
HAS_WEAKNESS (1)
→[Weakness]Allocation of Resources Without Limits or Throttling
Explore deeper with Ninja Signal's threat intelligence graph