CVE-2025-67779High· 7.5▾ TwilightIt was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, al…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
20%
It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe deserialization of payloads from HTTP requests to Server Function endpoints. This can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served.
react = 19.0.2react = 19.1.3react = 19.2.2next.js >= 13.3.0, < 14.2.35next.js >= 15.0.0, < 15.0.7next.js >= 15.1.0, < 15.1.11next.js >= 15.2.0, < 15.2.8next.js >= 15.3.0, < 15.3.8next.js >= 15.4.0, < 15.4.10next.js >= 15.5.0, < 15.5.9next.js >= 16.0.0, < 16.0.10next.js = 15.6.0next.js = 16.1.0Upgrade past the affected range:
next.js 16.0.10Connected by shared product, vendor, weakness, or advisory.
CVE-2025-55184High· 7.5A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopa…
CVE-2026-23864High· 7.5Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending s…
CVE-2025-55182Critical· 10.0A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-serve…
CVE-2026-23870High· 7.5A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following pac…
CVE-2021-21348Medium· 5.3XStream is a Java library to serialize objects to XML and back again
CVE-2021-21341High· 7.5XStream is a Java library to serialize objects to XML and back again