New React vulns leak secrets, invite DoS attacks
ID: a21cdbc4-8ce8-5528-98f4-3b870b8876eb
STIX ID: report--a21cdbc4-8ce8-5528-98f4-3b870b8876eb
Feed Name: The Register (Security)
Multiple high- and medium-severity vulnerabilities were disclosed in React Server Components (including CVE-2025-55184, CVE-2025-67779, and CVE-2025-55183) affecting several react-server-dom packages and versions; the flaws enable server hangs (infinite loops), potential source-code/secret leakage, and relate to a recently exploited critical RCE (React2Shell). Patches released earlier were incomplete, over 50 organizations have been impacted, and activity has been attributed to actors linked to North Korea and China, so immediate updates are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
