惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recent Announcements
Recent Announcements
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
B
Blog
T
The Blog of Author Tim Ferriss
J
Java Code Geeks
腾讯CDC
D
Docker
G
Google Developers Blog
D
DataBreaches.Net
雷峰网
雷峰网
Blog — PlanetScale
Blog — PlanetScale
S
SegmentFault 最新的问题
The Cloudflare Blog
有赞技术团队
有赞技术团队
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Stack Overflow Blog
Stack Overflow Blog
大猫的无限游戏
大猫的无限游戏
量子位
美团技术团队
aimingoo的专栏
aimingoo的专栏
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Engineering at Meta
Engineering at Meta
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

Fastly Blog

Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly
What is CVE-2026-23869? React Server Components Security ...
Matthew Mathur, Fastly Security Research Team · 2026-04-10 · via Fastly Blog

Senior Security Researcher, Fastly

Impacts, affected components, and what you can do immediately to stay secure

CVE-2026-23869: What you need to know

  • On April 8th, a new high-severity vulnerability (CVSS 7.5) was identified in React Server Components. This vulnerability can lead to Denial of Service. 

  • Fastly Next-Gen WAF customers can enable our new virtual patch to gain immediate protection against exploitation attempts while the underlying components are patched.

  • Affected components:

    • Nextjs 13.x, 14.x, 15.x, 16.x and affected packages using the App Router

    • react-server-dom-turbopack, react-server-dom-parcel, and react-server-dom-webpack versions:

      • 19.0.0 through 19.0.4

      • 19.1.0 through 19.1.5

      • 19.2.0 through 19.2.4

What are the impacts of CVE-2026-23869? 

CVE-2026-23869 can lead to denial of service in unpatched environments. According to Vercel, the vulnerability stems from a specially crafted HTTP request that can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage.

What can you do about it? 

While you should patch the underlying components as soon as possible, we understand that it can take time, so we have released a virtual patch for our Next-Gen WAF to provide immediate protection in the meantime. Follow the summarized steps below to access the Virtual Patch. 

  1. Go to Security > Next-Gen WAF > Workspaces.

  2. Click the gear icon next to the workspace you want to modify.

  3. Click Virtual patches.

  4. Find the desired virtual patch and enable it, optionally moving it from logging to blocking

We know our customers entrust us with the resilience of their business-critical services, and core to our company's mission is to have your back when surprises like CVE- 2026-23869 occur. That’s why we provide virtual patches to our customers to provide breathing room while they patch impacted systems. 

You can find additional details about virtual patches in our Docs and get detailed steps via our in-app AI assistant. Our teams are here for you as you navigate ongoing mitigation efforts, whether you’re a longstanding Fastly platform customer or new and in need of immediate protection. Let us know how we can help.