By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: New React RSC Vulnerabilities Enable DoS and Source Code Exposure
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > New React RSC Vulnerabilities Enable DoS and Source Code Exposure
Tech News

New React RSC Vulnerabilities Enable DoS and Source Code Exposure

By Viral Trending Content 3 Min Read
Share
SHARE

Dec 12, 2025Ravie LakshmananSoftware Security / Vulnerability

The React team has released fixes for two new types of flaws in React Server Components (RSC) that, if successfully exploited, could result in denial-of-service (DoS) or source code exposure.

The team said the issues were found by the security community while attempting to exploit the patches released for CVE-2025-55182 (CVSS score: 10.0), a critical bug in RSC that has since been weaponized in the wild.

The three vulnerabilities are listed below –

  • CVE-2025-55184 (CVSS score: 7.5) – A pre-authentication denial of service vulnerability arising from unsafe deserialization of payloads from HTTP requests to Server Function endpoints, triggering an infinite loop that hangs the server process and may prevent future HTTP requests from being served
  • CVE-2025-67779 (CVSS score: 7.5) – An incomplete fix for CVE-2025-55184 that has the same impact
  • CVE-2025-55183 (CVSS score: 5.3) – An information leak vulnerability that may cause a specifically crafted HTTP request sent to a vulnerable Server Function to return the source code of any Server Function

However, successful exploitation of CVE-2025-55183 requires the existence of a Server Function that explicitly or implicitly exposes an argument that has been converted into a string format.

Cybersecurity

The flaws affecting the following versions of react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack –

  • CVE-2025-55184 and CVE-2025-55183 – 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1
  • CVE-2025-67779 – 19.0.2, 19.1.3 and 19.2.2

Security researchers RyotaK and Shinsaku Nomura have been credited with reporting the two DoS bugs to the Meta Bug Bounty program, while Andrew MacPherson has been acknowledged for reporting the information leak flaw.

Users are advised to update to versions 19.0.3, 19.1.4, and 19.2.3 as soon as possible, particularly in light of active exploration of CVE-2025-55182.

“When a critical vulnerability is disclosed, researchers scrutinize adjacent code paths looking for variant exploit techniques to test whether the initial mitigation can be bypassed,” the React team said. “This pattern shows up across the industry, not just in JavaScript. Additional disclosures can be frustrating, but they are generally a sign of a healthy response cycle.”

You Might Also Like

Can Google Pixel 10 Pro Fold Replace Your Laptop? I Switched To Find Out

The Ultra-Realistic AI Face Swapping Platform Driving Romance Scams

Bank of Ireland warns customers to be wary of “smishing” scams this Christmas

HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution

What cyber defenders can learn from emergency healthcare

TAGGED: Cyber Security, Cybersecurity, Denial of Service, Internet, JavaScript, Patch Management, React, software security, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article ChatGPT 5.2 vs Gemini 3 vs Claude : Which AI Fits Your Needs
Next Article Reddit sues Australia over under-16 ban on social media
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Democrats Demand Vote on ACA Credits Before House Recesses for Holidays
Politics
Greg Biffle’s Wife: All About Cristina Grossu & Their Marriage
Celebrity
Swansea City vs Wrexham Bet Builder Tips – 4/1 Championship Special, Analysis & Predictions
Sports
CEO of nuclear fusion firm Trump Media is merging with: High-velocity capital is critical to build quickly and efficiently. The concerns are secondary
Business
15 Massive Games of 2025 That Can Keep You Busy for 50–100 Hours
Gaming News
Solana Price Could Crash Below $5 – The Document That Has Taken The Community By Storm
Crypto
Can Google Pixel 10 Pro Fold Replace Your Laptop? I Switched To Find Out
Tech News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Democrats Demand Vote on ACA Credits Before House Recesses for Holidays

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Democrats Demand Vote on ACA Credits Before House Recesses for Holidays
December 18, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?