deployedbyai

The Deploy Log | Tools and products

CVE-2026-23869

A high-severity React Server Components vulnerability with CVSS 7.5 can cause denial of service, and Vercel deployed WAF rules to protect all hosted projects while requiring upgrades to patched versions 15.5.15 and 16.2.3.

Vercel | In Edition 29, Saturday 11 Apr 2026

SOURCE Vercel, Summary of CVE-2026-23869

Added to The Deploy Log Tuesday 15 Sep 2026, updated Thursday 17 Sep 2026. Read Edition 29, the edition that carried it.

The call on this one

What shipped is free. The call on it, what to do about it and the condition on that, opens with a signup: free, no card, every edition in full.

It becomes $50 a year, and signing up now keeps your first year free.