React flaw exposes Next.js servers to service disruption
A high-severity vulnerability in React Server Components can allow unauthenticated attackers to overwhelm vulnerable Next. js servers through specially crafted HTTP requests, potentially making affected applications unavailable. The flaw, identified as CVE-2026-23870 and tracked under security advisory GHSA-rv78-f8rc-xrxh, affects specific releases of React 19. Security maintainers have issued…
We haven't written up this one. Arabian Post has the full story — the link below goes straight to it.