CVE-2025-67779
HIGHReact Server Components 19.0.2, 19.1.3, 19.2.2 - Denial of Service via Unsafe Deserialization
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-67779. PoCs published by JSH-data.
AI-analyzed exploit summary The repository contains functional exploit code for CVE-2025-55184 and CVE-2025-67779, targeting React Flight Server. The PoC demonstrates a DoS via an infinite loop triggered by a crafted payload manipulating weak references and forced initialization cycles.
Description
It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe deserialization of payloads from HTTP requests to Server Function endpoints. This can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served.
Exploits (1)
The repository contains functional exploit code for CVE-2025-55184 and CVE-2025-67779, targeting React Flight Server. The PoC demonstrates a DoS via an infinite loop triggered by a crafted payload manipulating weak references and forced initialization cycles.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H