Security Update: DoS vulnerability in Next.js and React Server Components
PreviewUnverifiedAdded Sep 24, 2026
A denial-of-service (DoS) vulnerability (CVE-2026-23864, CVSS 7.5) has been disclosed affecting React Server Components (RSCs), a feature used by Next.js and other React metaframeworks. A malicious payload can cause memory exhaustion or excessive CPU consumption.
Topics: Security, Pricing, Observability, Developer tools
More Netlify releases
Every Netlify release| Date | Release | Type |
|---|---|---|
| Jan 29 | Agent Runners improvementsunverified Update | Update |
| Jan 19 | Security Update: Multiple vulnerabilities in React Router and Remixunverified Update | Update |
| Feb 5 | Claude Opus 4.6 now available in AI Gateway and Agent Runnersunverified Update | Update |
| Jan 16 | Security Update: DoS vulnerability in Node.jsunverified Update | Update |
| Jan 15 | Security Update: Multiple vulnerabilities in SvelteKitunverified Update | Update |
| Jan 14 | GPT-5.2-Codex Now Available in AI Gateway and Agent Runnersunverified Update | Update |
| Feb 13 | Sync changes with Agent Runnersunverified Update | Update |
| Jan 8 | Play Games While Agent Runners Do the Workunverified Update | Update |
Also shipped on Jan 26, 2026
Netlify in January 2026| Date | Company | Release | Product | Type |
|---|---|---|---|---|
| Jan 26 | DuckDB 1.4.4 Bugfix Releaseunverified | DuckDB | Update | |
| Jan 26 | WAF - WAF Release - 2026-01-26unverified | Cloudflare developer platform | Update | |
| Jan 26 | Tailscale v1.94.1unverified | Tailscale | Update | |
| Jan 26 | FigJam diagramming in Claudeunverified | Figma | Update | |
| Jan 26 | Compiler cache for builds and Workflowsunverified | Expo | Update | |
| Jan 26 | Webhooks Ingesterunverified | Resend | Update |
Sources: each vendor's own release notes, changelogs and GitHub releases, read daily to monthly by how often it posts. Logos via logo.dev; trademarks belong to their owners.