CVE-2025-55184

HIGH EXPLOITED NUCLEI

React Server Components <19.2.1 - DoS

Title source: llm

Description

A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints, which can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served.

Exploits (14)

nomisec WORKING POC 15 stars
by cybertechajju · dos
https://github.com/cybertechajju/CVE-2025-55184-POC-Expolit
nomisec NO CODE 7 stars
by ejpir · dos
https://github.com/ejpir/CVE-2025-55184
github SCANNER 2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2025/CVE-2025-55184
nomisec SCANNER 2 stars
by KkHackingLearning · poc
https://github.com/KkHackingLearning/CVE-2025-55184_Testing
nomisec WORKING POC 2 stars
by hans362 · dos
https://github.com/hans362/CVE-2025-55184-poc
nomisec SCANNER 1 stars
by yogeshkumar09 · poc
https://github.com/yogeshkumar09/CVE-2025-55184_Testing
nomisec WRITEUP 1 stars
by shubham-01-star · poc
https://github.com/shubham-01-star/OpsGuard-simulation
nomisec SCANNER 1 stars
by KingHacker353 · dos
https://github.com/KingHacker353/CVE-2025-55184
nomisec WORKING POC
by JSH-data · poc
https://github.com/JSH-data/CVE-2025-55184_CVE-2025-67779
nomisec SUSPICIOUS
by yogeshkumar09 · poc
https://github.com/yogeshkumar09/yogeshkumar09.github.io
nomisec WORKING POC
by Tarekhshaikh13 · poc
https://github.com/Tarekhshaikh13/CVE-2025-55184
nomisec WORKING POC
by BakhodiribnYashinibnMansur · dos
https://github.com/BakhodiribnYashinibnMansur/CVE-2025-55184
vulncheck_xdb SCANNER
dos
https://github.com/Kajal5414/CVE-2025-55184_Testing
vulncheck_xdb WRITEUP
dos
https://github.com/StealthMoud/react-server-cve-lab

Nuclei Templates (1)

React Server Components - Denial of Service
HIGHVERIFIEDby DhiyaneshDk
Shodan: http.component:"Next.js"

Scores

CVSS v3 7.5
EPSS 0.2623
EPSS Percentile 96.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

VulnCheck KEV 2026-04-15
CWE
CWE-502
Status published
Products (5)
facebook/react 19.0.0 - 19.0.2
npm/react-server-dom-parcel 19.0.0 - 19.0.2npm
npm/react-server-dom-turbopack 19.0.0 - 19.0.2npm
npm/react-server-dom-webpack 19.0.0 - 19.0.2npm
vercel/next.js 15.6.0 (46 CPE variants)
Published Dec 11, 2025
Tracked Since Feb 18, 2026