React2DoS: One Malicious Form Submit, and Your Server's Done
Picture this: a user submits a form on your Next.js site. Boom—your server freezes for seconds, maybe minutes. That's React2DoS in action, turning RSC's clever streaming into a DoS nightmare.
CVE WatchApr 11, 20263 min read
⚡ Key Takeaways
React2DoS crashes servers with minimal payloads via Flight's recursive reference flaws𝕏
Exposes risks in RSC shift to server-side logic and custom streaming𝕏
Patch immediately—edge runtimes hit hardest, adoption may stall𝕏
The 60-Second TL;DR
React2DoS crashes servers with minimal payloads via Flight's recursive reference flaws
Exposes risks in RSC shift to server-side logic and custom streaming
Patch immediately—edge runtimes hit hardest, adoption may stall