← Back to CVE List
CVE-2025-55184NVD
Vulnerability Summary
A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints, which can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served.
CVSS v3.1 Base Metrics — Score 7.5 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityNone
AvailabilityHigh
Affected & Patched Versions
- Facebook React >= 19.0.0 and < 19.0.2
- Facebook React >= 19.1.0 and < 19.1.3
- Facebook React >= 19.2.0 and < 19.2.2
- Vercel Next.js >= 13.3.0 and < 14.2.35
- Vercel Next.js >= 15.0.0 and < 15.0.7
- Vercel Next.js >= 15.1.0 and < 15.1.11
- Vercel Next.js >= 15.2.0 and < 15.2.8
- Vercel Next.js >= 15.3.0 and < 15.3.8
- Vercel Next.js >= 15.4.0 and < 15.4.10
- Vercel Next.js >= 15.5.0 and < 15.5.9
- Vercel Next.js >= 16.0.0 and < 16.0.10
- Vercel Next.js
- Facebook React 19.0.2
- Facebook React 19.1.3
- Facebook React 19.2.2
- Vercel Next.js 14.2.35
- Vercel Next.js 15.0.7
- Vercel Next.js 15.1.11
- Vercel Next.js 15.2.8
- Vercel Next.js 15.3.8
- Vercel Next.js 15.4.10
- Vercel Next.js 15.5.9
- Vercel Next.js 16.0.10