CVE-2025-55184High· 7.5▾ MidnightPoC availableA pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopa…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 13.4 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
67%
9 GitHub repos · Nuclei ×1 (last check)
A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints, which can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served.
react >= 19.0.0, < 19.0.2react >= 19.1.0, < 19.1.3react >= 19.2.0, < 19.2.2next.js >= 13.3.0, < 14.2.35next.js >= 15.0.0, < 15.0.7next.js >= 15.1.0, < 15.1.11next.js >= 15.2.0, < 15.2.8next.js >= 15.3.0, < 15.3.8next.js >= 15.4.0, < 15.4.10next.js >= 15.5.0, < 15.5.9next.js >= 16.0.0, < 16.0.10next.js = 15.6.0next.js = 16.1.0Upgrade past the affected range:
react 19.2.2next.js 16.0.10Connected by shared product, vendor, weakness, or advisory.
CVE-2025-67779High· 7.5It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case
CVE-2025-55182Critical· 10.0A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-serve…
CVE-2026-23864High· 7.5Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending s…
CVE-2021-23758High· 8.1All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
CVE-2020-36180High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.
CVE-2020-36179High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.