Skip to content

Security Update: DoS vulnerability in Next.js and React Server Components

PreviewUnverifiedAdded Sep 24, 2026

A denial-of-service (DoS) vulnerability (CVE-2026-23864, CVSS 7.5) has been disclosed affecting React Server Components (RSCs), a feature used by Next.js and other React metaframeworks. A malicious payload can cause memory exhaustion or excessive CPU consumption.

Topics: Security, Pricing, Observability, Developer tools

Netlify's release notes

More Netlify releases

Every Netlify release

Also shipped on Jan 26, 2026

Netlify in January 2026

Sources: each vendor's own release notes, changelogs and GitHub releases, read daily to monthly by how often it posts. Logos via logo.dev; trademarks belong to their owners.

New releases by email

Tuesday mornings: the week's data, AI and developer-tools releases, only in weeks when something shipped.

Double opt-in. Unsubscribe any time.