BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

React Fixes New DoS, Source Leak Flaws in Server Components

React patches multiple vulnerabilities in Server Components causing DoS and source code leaks, urges updates to latest versions

  • React released patches for two new vulnerabilities in React Server Components that could cause denial-of-service or source code leaks.
  • The flaws were discovered during attempts to exploit a previous critical vulnerability, CVE-2025-55182, which has been active in the wild.
  • Three related vulnerabilities have been identified: CVE-2025-55184 and CVE-2025-67779 cause server hangs due to unsafe deserialization, while CVE-2025-55183 risks exposing source code.
  • These issues affect multiple versions of react-server-dom packages, with updates available in versions 19.0.3, 19.1.4, and 19.2.3.
  • Security researchers credited for reporting these flaws include RyotaK, Shinsaku Nomura, and Andrew MacPherson.

React has issued security updates addressing two new vulnerabilities in its Server Components framework, potentially leading to denial-of-service (DoS) attacks or unintended source code exposure. These fixes were released on December 11, 2025, after these flaws were discovered amid efforts to exploit an earlier critical vulnerability known as CVE-2025-55182, which has seen active exploitation here.

- Advertisement -

The newly disclosed bugs include CVE-2025-55184 and CVE-2025-67779, both rated with a CVSS score of 7.5. They arise from unsafe deserialization of payloads in HTTP requests sent to Server Function endpoints, which can cause the server to enter an infinite loop and become unresponsive, blocking future requests. CVE-2025-67779 is noted as an incomplete fix for CVE-2025-55184 and has the same impact.

Another vulnerability, CVE-2025-55183, rated 5.3 for severity, involves an information leak. A carefully crafted HTTP request can cause a Server Function to reveal its source code. However, exploiting this flaw requires that a Server Function exposes an argument converted to string format.

The affected software versions include react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack versions 19.0.0 through 19.2.1 for CVE-2025-55184 and CVE-2025-55183, and versions 19.0.2 through 19.2.2 for CVE-2025-67779. Users are urged to upgrade to versions 19.0.3, 19.1.4, or 19.2.3 promptly.

Security researchers RyotaK and Shinsaku Nomura reported the denial-of-service vulnerabilities to the Meta Bug Bounty program, while Andrew MacPherson disclosed the information leak flaw. According to the React team, “When a critical vulnerability is disclosed, researchers scrutinize adjacent code paths looking for variant exploit techniques to test whether the initial mitigation can be bypassed.” They added that such additional disclosures, though sometimes frustrating, indicate an active and effective security response cycle.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Trump Crypto Project Rated Among Industry’s Riskiest

The newly launched ratings firm CORE3 has assigned a 'DDD' risk grade to the...

U.S. Crypto Clarity Act Nears Key Senate Deal

Coinbase Chief Legal Officer Paul Grewal announced lawmakers are nearing a resolution on disputed...

Ex-FTX engineer Nishad Singh fined $3.7 million

Former FTX head of engineering Nishad Singh settled a Commodity Futures Trading Commission (CFTC)...

Tether’s Jesse Spiro to Chair $100M Crypto Super PAC

Tether's Head of Government Affairs, Jesse Spiro, will chair the crypto-funded Fellowship PAC ahead...

CERT-UA Impersonated, New RAT Attack Hits Ukraine

The Computer Emergency Response Team of Ukraine (CERT-UA) was impersonated in a phishing campaign...

Must Read

9 DePIN Programs For Passive Income

Here’s something most people don’t realize: your smartphone and PC can generate passive income with almost no effort.I’m not talking about clicking ads for...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading