Executive brief
React Server Components are JavaScript libraries used by web applications to render components on the server. An incomplete security patch allows attackers to send specially crafted requests that crash the server, causing service outages. Applications using React Server Components bundled with Webpack, Parcel, or Turbopack are affected.
Technical details
The vulnerability is a denial of service flaw stemming from improper handling of deserialization and uncontrolled resource consumption (CWE-400, CWE-502). A prior fix for CVE-2025-55184 was incomplete, leaving specific attack vectors unmitigated. The flaw is reachable over the network without authentication or user interaction, allowing remote attackers to trigger server resource exhaustion or crashes. Patches are available in versions 19.0.3, 19.1.4, and 19.2.3 of affected libraries, and immediate upgrade is recommended.
Affected products
- Meta react-server-dom-webpack 19.0.2, 19.1.3, 19.2.2
- Meta react-server-dom-parcel 19.0.2, 19.1.3, 19.2.2
- Meta react-server-dom-turbopack 19.0.2, 19.1.3, 19.2.2
Timeline
- 2025-12-12: disclosed: GHSA-7gmr-mq3h-m5h9 published; incomplete patch vulnerability disclosed
- 2025-12-12: patched: Fixes backported to 19.0.3, 19.1.4, 19.2.3