Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
open-source-dependency-vulnerabilityinternet-facing-service-vulnerabilitywidely-deployed-product-advisorypatch-regression

Denial-of-Service and Source Code Exposure Vulnerabilities in React Server Components

Updated 3mo agoFirst seen Dec 12, 20258 sources

Security researchers have identified three new vulnerabilities in React Server Components (RSC) following the recent patch for the critical React2Shell exploit. These flaws include two high-severity Denial-of-Service (DoS) vulnerabilities (CVE-2025-55184 and CVE-2025-67779) and a medium-severity Source Code Exposure vulnerability (CVE-2025-55183). The DoS vulnerabilities allow attackers to send malicious HTTP requests to Server Function endpoints, triggering infinite loops that hang the server and exhaust CPU resources, effectively taking applications offline. The source code exposure flaw enables attackers to craft HTTP requests that can leak the source code of server functions, potentially exposing hardcoded secrets or sensitive logic, though runtime secrets remain protected.

The affected packages are react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack, impacting React versions 19.0.0 through 19.2.2 and frameworks such as Next.js, Waku, and React Router. Initial patches released for these vulnerabilities were incomplete, necessitating immediate upgrades to versions 19.0.3, 19.1.4, and 19.2.3 to ensure full protection. The vulnerabilities were discovered by security researchers during attempts to bypass previous mitigations, highlighting the importance of rapid patch adoption and ongoing scrutiny of critical code paths after major disclosures. Users are strongly advised to update affected packages and monitor official channels for further security updates.

Share:
Denial-of-Service and Source Code Exposure Vulnerabilities in React Server Components
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Dec 18, 20256mo ago

Vercel deploys WAF protections for hosted projects

Vercel said it deployed WAF rules to help protect projects hosted on its platform from the React Server Components vulnerabilities affecting React 19 and Next.js. It emphasized that these protections are temporary and that customers still need to upgrade to patched React and Next.js versions.

Dec 11, 20257mo ago

Akamai deploys protections and publishes mitigation guidance

Akamai announced Adaptive Security Engine Rapid Rules and related detection and mitigation guidance for customers affected by CVE-2025-55183 and CVE-2025-55184. The company also provided asset-identification queries and recommended prompt vendor patching as the primary mitigation.

React discloses the new CVEs and releases patched versions

React publicly disclosed the new vulnerabilities on its blog and released fixes backported to versions 19.0.3, 19.1.4, and 19.2.3. The advisory warned that crafted HTTP requests could hang server processes or expose Server Function source code, and urged immediate upgrades.

Researchers identify new RSC DoS and source code exposure flaws

During follow-up security research on React2Shell, researchers Andrew MacPherson, RyotaK, and Shinsaku Nomura discovered additional React Server Components vulnerabilities: DoS issues CVE-2025-55184 and CVE-2025-67779, and source code exposure flaw CVE-2025-55183. The bugs affect react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack across vulnerable React 19.x releases.

Dec 4, 20257mo ago

React2Shell RCE flaw is disclosed and patched incompletely

Before the newly disclosed issues, React patched the critical React Server Components remote code execution flaw CVE-2025-55182 ("React2Shell"). Subsequent research found the initial mitigations were incomplete, leaving room for bypasses and follow-on vulnerabilities.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

20 LINKEDOpen in app
Threat actors
1 linked
Affected products
1 linked
React
Organizations
14 linked
VercelReactMeta PlatformsAkamai TechnologiesXcape IncAmazon Web ServicesSocketPalo Alto NetworksCloudflareGMO Flatt SecurityCoalitionWizGuardicoreBitforest
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.