CVE-2026-23870 is a denial-of-service vulnerability in Next.js server actions where an attacker can craft a malicious POST request with thousands of nested form pointers and fields, causing React's request parsing to perform millions of string checks on a single thread, freezing the server for seconds. The vulnerability requires no authentication and can be exploited by extracting the action ID from public HTML or JavaScript files.