logo

New Vulnerabilities in React Server Components Allow DoS Attacks and Source Code Leaks

ID: c8019fcb-257a-5e58-bf6f-a6f34ba7a930

STIX ID: report--c8019fcb-257a-5e58-bf6f-a6f34ba7a930

Feed Name: cybersecurityNews.com

Threat Score
65/100

Date Published: 2025-12-12

Date Updated: 2026-04-21

Author: Guru Baran

...
...

React disclosed three vulnerabilities in React Server Components that allow for DoS (infinite-loop during deserialization) and potential source-code exposure; two DoS issues are rated High (CVSS 7.5) and one exposure is Medium (CVSS 5.3). Users of react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack — and frameworks such as Next.js, Waku, and React Router — are advised to upgrade immediately to the patched versions (19.0.3, 19.1.4, 19.2.3) because earlier fixes were incomplete.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.