{"id":"CVE-2025-55183","title":"An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom…","summary":"An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","vendor":"vercel","product":"next.js","affected":["next.js >= 15.0.0, < 15.0.7","next.js >= 15.1.0, < 15.1.11","next.js >= 15.2.0, < 15.2.8","next.js >= 15.3.0, < 15.3.8","next.js >= 15.4.0, < 15.4.10","next.js >= 15.5.0, < 15.5.9","next.js >= 16.0.0, < 16.0.10","next.js = 15.6.0","next.js = 16.1.0","react >= 19.0.0, < 19.0.2","react >= 19.1.0, < 19.1.3","react >= 19.2.0, < 19.2.2"],"patched":["next.js 16.0.10","react 19.2.2"],"published":"2025-12-11","updated":"2026-10-07","sourceUpdated":"2026-10-07T20:10:01.970","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-55183","references":[{"url":"https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components","label":"cve-assign@fb.com"},{"url":"https://www.facebook.com/security/advisories/cve-2025-55183","label":"cve-assign@fb.com"}],"tags":["nvd","exploit-available"],"epss":0.64233,"epssPercentile":0.99212,"exploits":{"github":6,"githubRepos":["https://github.com/williavs/nextjs-security-update","https://github.com/kimtruth/CVE-2025-55183-poc","https://github.com/StealthMoud/react-server-cve-lab"],"checkedAt":"2026-10-07T20:47:22.824Z"},"exploitAvailable":true,"ingestedAt":"2026-10-07T20:46:46.863Z","slug":"CVE-2025-55183","body":"## Overview\n\nAn information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. A specifically crafted HTTP request sent to a vulnerable Server Function may unsafely return the source code of any Server Function. Exploitation requires the existence of a Server Function which explicitly or implicitly exposes a stringified argument.\n\n## Affected\n\n- `next.js >= 15.0.0, < 15.0.7`\n- `next.js >= 15.1.0, < 15.1.11`\n- `next.js >= 15.2.0, < 15.2.8`\n- `next.js >= 15.3.0, < 15.3.8`\n- `next.js >= 15.4.0, < 15.4.10`\n- `next.js >= 15.5.0, < 15.5.9`\n- `next.js >= 16.0.0, < 16.0.10`\n- `next.js = 15.6.0`\n- `next.js = 16.1.0`\n- `react >= 19.0.0, < 19.0.2`\n- `react >= 19.1.0, < 19.1.3`\n- `react >= 19.2.0, < 19.2.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `next.js 16.0.10`\n- `react 19.2.2`","depth":"twilight","depthScore":54,"depthScoreParts":{"impact":29.2,"likelihood":12.8,"exploitation":12,"ransomware":0},"changes":[]}