Skip to content

CVE-2025-55184

CVE

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
December 11, 2025
Last Seen
May 8, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

Multiple critical vulnerabilities affecting React Server Components and .js have been disclosed, including denial of service, server-side request forgery, and middleware bypass issues. These flaws impact versions 13.x to 16.x of .js and 19.x of React Server Components. Vercel has released patches fo...

Two vulnerabilities have been identified in React Server Components versions 19.0.0 to 19.2.1. CVE-2025-55184 is a pre-authentication denial of service vulnerability, while CVE-2025-55183 is an information leak vulnerability that can expose source code through crafted HTTP requests. The affected pac...

Two vulnerabilities have been identified in the React Server Components (RSC) protocol during a security review of patches for React2Shell. These vulnerabilities do not allow for Remote Code Execution, and the existing patch for React2Shell remains effective. The vulnerabilities were discovered by s...

Public Exploits

Checking GitHub for proof-of-concept code…