source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
SATURDAY, OCTOBER 10, 2026
  1. 001Hacker NewsOCT · 09English

    CVE-2026-23870: A Single Post Freezes Any Next.js Server

    CVE-2026-23870 is a denial-of-service vulnerability in Next.js server actions where an attacker can craft a malicious POST request with thousands of nested form pointers and fields, causing React's request parsing to perform millions of string checks on a single thread, freezing the server for seconds. The vulnerability requires no authentication and can be exploited by extracting the action ID from public HTML or JavaScript files.

    By Simon Koeck