---
id: CVE-2025-55184
title: >-
  A pre-authentication denial of service vulnerability exists in React Server
  Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1,
  including the following packages: react-server-dom-parcel,
  react-server-dom-turbopa…
summary: >-
  A pre-authentication denial of service vulnerability exists in React Server
  Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1,
  including the following packages: react-server-dom-parcel,
  react-server-dom-turbopa…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-502
vendor: facebook
product: react
affected:
  - 'react >= 19.0.0, < 19.0.2'
  - 'react >= 19.1.0, < 19.1.3'
  - 'react >= 19.2.0, < 19.2.2'
  - 'next.js >= 13.3.0, < 14.2.35'
  - 'next.js >= 15.0.0, < 15.0.7'
  - 'next.js >= 15.1.0, < 15.1.11'
  - 'next.js >= 15.2.0, < 15.2.8'
  - 'next.js >= 15.3.0, < 15.3.8'
  - 'next.js >= 15.4.0, < 15.4.10'
  - 'next.js >= 15.5.0, < 15.5.9'
  - 'next.js >= 16.0.0, < 16.0.10'
  - next.js = 15.6.0
  - next.js = 16.1.0
patched:
  - react 19.2.2
  - next.js 16.0.10
published: '2025-12-11'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-55184'
references:
  - url: >-
      https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components
    label: cve-assign@fb.com
  - url: 'https://www.facebook.com/security/advisories/cve-2025-55184'
    label: cve-assign@fb.com
  - url: 'https://github.com/KingHacker353/CVE-2025-55184'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - exploit-available
epss: 0.66882
epssPercentile: 0.99277
exploits:
  github: 9
  githubRepos:
    - 'https://github.com/cybertechajju/CVE-2025-55184-POC-Expolit'
    - 'https://github.com/ejpir/CVE-2025-55184'
    - 'https://github.com/hans362/CVE-2025-55184-poc'
  nuclei:
    - CVE-2025-55184
  checkedAt: '2026-10-07T20:47:22.824Z'
exploitAvailable: true
ingestedAt: '2026-10-07T20:46:46.863Z'
---

## Overview

A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints, which can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served.

## Affected

- `react >= 19.0.0, < 19.0.2`
- `react >= 19.1.0, < 19.1.3`
- `react >= 19.2.0, < 19.2.2`
- `next.js >= 13.3.0, < 14.2.35`
- `next.js >= 15.0.0, < 15.0.7`
- `next.js >= 15.1.0, < 15.1.11`
- `next.js >= 15.2.0, < 15.2.8`
- `next.js >= 15.3.0, < 15.3.8`
- `next.js >= 15.4.0, < 15.4.10`
- `next.js >= 15.5.0, < 15.5.9`
- `next.js >= 16.0.0, < 16.0.10`
- `next.js = 15.6.0`
- `next.js = 16.1.0`

## Remediation

Upgrade past the affected range:

- `react 19.2.2`
- `next.js 16.0.10`
