CVEFinder.io

CVE-2025-55184

⚠️ high
🔍 Scan for this CVE
Summary

A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints, which can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served.

CVSS Score
7.5
High
EPSS Score
20.7
Exploit Probability
Published Date
2025-12-11
First Seen: 2026-01-05
📊 Relative Risk Intelligence

This CVE is Moderate Risk - more severe than 69.4% of all 317,883 vulnerabilities in our database.

#97,299
Above average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: Dec 15, 2025
🔍 Exploitation Status
Poc
Proof-of-concept available
⚙️ Automatable
YES
Can be exploited automatically
💥 Technical Impact
Partial
Limited system impact
SSVC data provided by CISA
Last Modified 2025-12-15
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE IDs (Weakness Types)

📦 Affected Products 13

💣 Public Exploits 1 PRO

Loading exploits...

Loading exploit information...

🔗 References 3

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-27977 🔶 medium 5.4 0.0 Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1... 2026-03-18
CVE-2026-27978 🔶 medium 4.3 0.0 Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1... 2026-03-18
CVE-2026-27979 ⚠️ high 7.5 0.0 Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1... 2026-03-18
CVE-2026-27980 ⚠️ high 7.5 0.0 Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 1... 2026-03-18
CVE-2026-29057 🔶 medium 6.5 0.1 Next.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 1... 2026-03-18
CVE-2026-23864 ⚠️ high 7.5 0.9 Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-ser... 2026-01-26
These CVEs affect the same products