CVE-2025-55184
HIGH EXPLOITED NUCLEIReact Server Components <19.2.1 - DoS
Title source: llmDescription
A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints, which can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served.
Exploits (14)
nomisec
WORKING POC
15 stars
by cybertechajju · dos
https://github.com/cybertechajju/CVE-2025-55184-POC-Expolit
github
SCANNER
2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2025/CVE-2025-55184
nomisec
SCANNER
2 stars
by KkHackingLearning · poc
https://github.com/KkHackingLearning/CVE-2025-55184_Testing
nomisec
SCANNER
1 stars
by yogeshkumar09 · poc
https://github.com/yogeshkumar09/CVE-2025-55184_Testing
nomisec
WRITEUP
1 stars
by shubham-01-star · poc
https://github.com/shubham-01-star/OpsGuard-simulation
nomisec
WORKING POC
by BakhodiribnYashinibnMansur · dos
https://github.com/BakhodiribnYashinibnMansur/CVE-2025-55184
Nuclei Templates (1)
React Server Components - Denial of Service
HIGHVERIFIEDby DhiyaneshDk
Shodan:
http.component:"Next.js"
Scores
CVSS v3
7.5
EPSS
0.2623
EPSS Percentile
96.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
VulnCheck KEV
2026-04-15
CWE
CWE-502
Status
published
Products (5)
facebook/react
19.0.0 - 19.0.2
npm/react-server-dom-parcel
19.0.0 - 19.0.2npm
npm/react-server-dom-turbopack
19.0.0 - 19.0.2npm
npm/react-server-dom-webpack
19.0.0 - 19.0.2npm
vercel/next.js
15.6.0 (46 CPE variants)
Published
Dec 11, 2025
Tracked Since
Feb 18, 2026