Summary of CVE-2026-23869
A high-severity vulnerability (CVSS 7.5) in React Server Components can cause Denial of Service via crafted HTTP requests that trigger excessive CPU usage in App Router Server Functions. Vercel deployed automated mitigations via the WAF, but a patch upgrade is required since the WAF is not full protection. The issue affects Next.js 13.x–16.x and users should upgrade to patched versions (e.g., Next.js 15.5.15 and 16.2.3) as soon as possible.