← Back to browse · API

CVE-2025-55184

Severity
HIGH
CVSS
7.5
EPSS
0.67291
Risk score
53.55
CISA KEV
No
PoC
No
Published
2025-12-11
Modified
2025-12-15
First seen
2026-08-07
Aliases
EUVD-2025-202877, GHSA-2M3V-V2M8-Q956
Products
Meta:react-server-dom-parcel 19.0.0 ≤19.0.1, Meta:react-server-dom-parcel 19.1.0 ≤19.1.2, Meta:react-server-dom-parcel 19.2.0 ≤19.2.1, Meta:react-server-dom-turbopack 19.0.0 ≤19.0.1, Meta:react-server-dom-turbopack 19.1.0 ≤19.1.2, Meta:react-server-dom-turbopack 19.2.0 ≤19.2.1, Meta:react-server-dom-webpack 19.0.0 ≤19.0.1, Meta:react-server-dom-webpack 19.1.0 ≤19.1.2, Meta:react-server-dom-webpack 19.2.0 ≤19.2.1
Sources
euvd EUVD-2025-202877

Description

A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints, which can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served.

References