CVE-2025-55183Medium· 5.3▾ TwilightPoC availableAn information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 29.2 · likelihood 12.8 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
64%
6 GitHub repos (last check)
An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. A specifically crafted HTTP request sent to a vulnerable Server Function may unsafely return the source code of any Server Function. Exploitation requires the existence of a Server Function which explicitly or implicitly exposes a stringified argument.
next.js >= 15.0.0, < 15.0.7next.js >= 15.1.0, < 15.1.11next.js >= 15.2.0, < 15.2.8next.js >= 15.3.0, < 15.3.8next.js >= 15.4.0, < 15.4.10next.js >= 15.5.0, < 15.5.9next.js >= 16.0.0, < 16.0.10next.js = 15.6.0next.js = 16.1.0react >= 19.0.0, < 19.0.2react >= 19.1.0, < 19.1.3react >= 19.2.0, < 19.2.2Upgrade past the affected range:
next.js 16.0.10react 19.2.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-44579High· 7.5Next.js is a React framework for building full-stack web applications
CVE-2026-44578High· 8.6Next.js is a React framework for building full-stack web applications
CVE-2025-29927Critical· 9.1Next.js middleware authorization bypass via x-middleware-subrequest
CVE-2026-94544Medium· 4.2Next.js is a React framework for building full-stack web applications
CVE-2026-94543Medium· 5.3Next.js is a React framework for building full-stack web applications
CVE-2026-94486Medium· 5.4Next.js is a React framework for building full-stack web applications