TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Imperva Blog

React2DoS (CVE-2026-23869): When the Flight Protocol Crashes at Takeoff

Yohann Sillam · 2026-04-09 · Read original ↗

ATT&CK techniques detected

1 predictions
T1190Exploit Public-Facing Application
39%
"one of the most used framework in the world and discover a finding with meaningful impact. this wouldn ’ t have been possible if researchers before didn ’ t pave the way with their investigations and their recent findings ( react2shell, cve ‑ 2026 ‑ 23864 … ). disclosure timeline…"

Summary

Executive Summary In this article, we disclose a new high severity unauthenticated remote denial‑of‑service vulnerability we identified and reported in React Server Components that we’ve dubbed “React2DoS”.  In this blog, we’ll analyze its impact and place it in the broader context of recently found Flight protocol vulnerabilities, especially CVE‑2026‑23864. Introduction We are in a phase […]

The post React2DoS (CVE-2026-23869): When the Flight Protocol Crashes at Takeoff appeared first on Blog.