BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

React Fixes New DoS, Source Leak Flaws in Server Components

React patches multiple vulnerabilities in Server Components causing DoS and source code leaks, urges updates to latest versions

  • React released patches for two new vulnerabilities in React Server Components that could cause denial-of-service or source code leaks.
  • The flaws were discovered during attempts to exploit a previous critical vulnerability, CVE-2025-55182, which has been active in the wild.
  • Three related vulnerabilities have been identified: CVE-2025-55184 and CVE-2025-67779 cause server hangs due to unsafe deserialization, while CVE-2025-55183 risks exposing source code.
  • These issues affect multiple versions of react-server-dom packages, with updates available in versions 19.0.3, 19.1.4, and 19.2.3.
  • Security researchers credited for reporting these flaws include RyotaK, Shinsaku Nomura, and Andrew MacPherson.

React has issued security updates addressing two new vulnerabilities in its Server Components framework, potentially leading to denial-of-service (DoS) attacks or unintended source code exposure. These fixes were released on December 11, 2025, after these flaws were discovered amid efforts to exploit an earlier critical vulnerability known as CVE-2025-55182, which has seen active exploitation here.

- Advertisement -

The newly disclosed bugs include CVE-2025-55184 and CVE-2025-67779, both rated with a CVSS score of 7.5. They arise from unsafe deserialization of payloads in HTTP requests sent to Server Function endpoints, which can cause the server to enter an infinite loop and become unresponsive, blocking future requests. CVE-2025-67779 is noted as an incomplete fix for CVE-2025-55184 and has the same impact.

Another vulnerability, CVE-2025-55183, rated 5.3 for severity, involves an information leak. A carefully crafted HTTP request can cause a Server Function to reveal its source code. However, exploiting this flaw requires that a Server Function exposes an argument converted to string format.

The affected software versions include react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack versions 19.0.0 through 19.2.1 for CVE-2025-55184 and CVE-2025-55183, and versions 19.0.2 through 19.2.2 for CVE-2025-67779. Users are urged to upgrade to versions 19.0.3, 19.1.4, or 19.2.3 promptly.

Security researchers RyotaK and Shinsaku Nomura reported the denial-of-service vulnerabilities to the Meta Bug Bounty program, while Andrew MacPherson disclosed the information leak flaw. According to the React team, “When a critical vulnerability is disclosed, researchers scrutinize adjacent code paths looking for variant exploit techniques to test whether the initial mitigation can be bypassed.” They added that such additional disclosures, though sometimes frustrating, indicate an active and effective security response cycle.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

AnyDesk Linux pre-auth RCE exploit gives root access

Security researchers published AnyPwn, a working exploit for a pre-authentication remote code execution flaw...

CleanSpark Ends Monthly Bitcoin Reports, Cites Data Center Growth

CleanSpark produced 529 BTC in September, averaging 17.64 BTC per day, and holds 13,530...

China doc exposes pig butchering scam border horrors

China released a documentary series exposing pig butchering scams across Southeast AsiaNearly 100,000 law...

Qureshi Slams Drake’s ‘Bunker Mode’ as Crypto Doomerism

Dragonfly managing partner Haseeb Qureshi called Ethereum researcher Justin Drake’s “bunker mode” warning “cryptographic...

CISA Adds 5 Flax Typhoon Exploited Flaws to KEV Catalog

CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog after China-linked threat actor...

Must Read

How to Buy VPN With Bitcoin Using CyberGhost VPN

In this step-by-step guide, you will learn how to purchase a VPN (Virtual Private Network) subscription using Bitcoin, a popular cryptocurrency, and CyberGhost VPN,...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading