What WebPulse reported · 2 analyses
React Server Components Carry a DoS Flaw. Every RSC Framework Inherits It.
CVE-2026-23869 scores CVSS 7.5. A cyclic payload in React Flight protocol exhausts CPU for 60 seconds per request.
June 21, 2026
Next.js Authorization Bypass: A Crafted Query Parameter Changes Your Route Without Changing the URL. CVE-2026-44574.
Specially crafted query parameters alter dynamic route values while leaving the visible URL path unchanged, bypassing middleware-based authorization in Next.js
June 15, 2026
Related vulnerabilities