CVE-2025-55184Disclosure(facebook / next.js)

HIGHCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch facebook next.js systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints, which can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served.

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • next.js
  • react

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 6 observed days

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 2 mentions (2026-02-26); latest day: 1
  • 8 total mentions across 6 days

Affected systems

Products
next.jsreact

2 versions affected across 2 products

Deep dive

Activity timeline8 mentions / 6d
01122Mentions · 2026-02-26: 2Mentions · 2026-03-15: 1Mentions · 2026-03-21: 2Mentions · 2026-04-23: 1Mentions · 2026-04-24: 1Mentions · 2026-05-07: 1PoC Mentioned / Linked · 2026-04-23: 1Active Exploitation · 2026-02-26: 1Active Exploitation · 2026-04-23: 1Patch / Workaround · 2026-02-26: 1Patch / Workaround · 2026-04-23: 1Patch / Workaround · 2026-04-24: 1Patch / Workaround · 2026-05-07: 1Technical Details · 2026-02-26: 2Technical Details · 2026-03-15: 1Technical Details · 2026-03-21: 1Technical Details · 2026-04-23: 1Technical Details · 2026-04-24: 1Technical Details · 2026-05-07: 102-2603-1503-2104-2304-2405-07
Signal classification4 categories
Disclosure
337.5%
Active Exploitation
225.0%
General
225.0%
Patch
112.5%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-262
Active Exploitation1General1
2026-03-151
Disclosure1
2026-03-212
Disclosure1General1
2026-04-231
Active Exploitation1
2026-04-241
Patch1
2026-05-071
Disclosure1
Full discourse8 posts
  • X@TheMsterDoctor1
    General

    I just lost a $50,000 bounty. Marked as duplicate. CVE-2025-55184 — critical platform protection bypass. Someone submitted it before me. Most people would quit after that. I won’t. Because this is the game: → You can be right and still lose → You can find critical bugs and get $0 → You’re competing against the best hackers in the world This is what real bug bounty looks like. No shortcuts. No guarantees. Only skill, speed, and obsession. Next one won’t be $50K. It’ll be bigger.

    Post summary

    The post describes a lost $50,000 bounty on CVE‑2025‑55184 and hints at future prospects, but it provides no technical or actionable details about the vulnerability.

    191413007827.0K
    34.9K followersView on X
  • Music Anarchy 🗸@AuAnarchy
    Disclosure

    @TheMsterDoctor1 CVE-2025-55184 is a denial-of-service vulnerability in React Server Components. A duplicate closure notice doesn't show what the bounty would have been.

    Post summary

    The post announces a new denial‑of‑service vulnerability (CVE‑2025‑55184) affecting React Server Components, with no further technical details, PoC, or mitigation information provided.

    100811.4K
    332 followersView on X
  • Stefano Saitta@nerder_
    General

    @rauchg Your non-vibecoded framework Next also had 1 critical (CVE-2025-66478), 1 high (CVE-2025-55184), and 1 medium (CVE-2025-55183) security vulnerabilities.

    Post summary

    The tweet simply enumerates three CVEs with their severity ratings, offering no additional technical or mitigation details.

    00040144
    164 followersView on X
  • Aikido Community Japan@AikidoCommJP
    Disclosure

    ⚠️ 新着記事 React & Next.jsのDoS脆弱性(CVE-2025-55184) https://aikido-community.jp/blog/react-next-js-dos-vulnerability-cve-2025-55184 #React #Next.js #CVE #Aikido #セキュリティ

    Post summary

    The post announces a new article about the DoS vulnerability CVE‑2025‑55184 in React & Next.js, but does not provide PoC, exploit code, active exploitation evidence, or a patch.

    00020204
    16 followersView on X
  • Rodrigo Moreno@RodMoreno_
    Active Exploitation

    Interesting timing to lecture about security. In the last 3 months alone, your stack shipped: • CVE-2025-66478 — RCE, CVSS 10.0. Exploited in the wild by nation-state actors. • CVE-2025-55184 — DoS, CVSS 7.5. Initial patch was incomplete, required a 2nd fix.

    Post summary

    The post notes that CVE-2025-66478, a critical RCE, has been actively exploited by nation‑state actors, and that the initial patch for CVE-2025-55184 was incomplete, requiring a second fix.

    10010138
    317 followersView on X
  • DataHogo@DataHogo
    Patch

    You patched CVE-2025-55184. But the patch had a hole. CVE-2025-67779 — the incomplete fix that left developers who already updated still vulnerable to DoS. If you updated once and moved on, read this. https://www.datahogo.com/en/blog/cve-2025-67779-nextjs-dos-incomplete-patch

    Post summary

    The post alerts readers that the patches for CVE‑2025‑67779 are incomplete, leaving developers exposed to a DoS attack.

    01000581
    3 followersView on X
  • DataHogo@DataHogo
    Active Exploitation

    Next.js App Router can be sent into an infinite loop with one HTTP request. CVE-2025-55184 — a DoS in the React Flight parser that went live in the wild before the patch dropped. No auth needed. No special headers. Just a malformed POST. https://www.datahogo.com/en/blog/cve-2025-55184-nextjs-dos-infinite-loop

    Post summary

    CVE‑2025‑55184 is a DoS flaw in Next.js’s React Flight parser that allows a single malformed POST request to trigger an infinite loop; the vulnerability was already exploited in the wild before a patch was released.

    10000546
    3 followersView on X
  • Grok@grok
    Disclosure

    The vulnerabilities are: - CVE-2025-55182: Critical unauthenticated RCE in React Server Components (v19.0-19.2) & Next.js (15-16) via malicious payload deserialization to server functions. - CVE-2025-55183: Server function source leak via insufficient validation. - CVE-2025-55184: DoS via cyclical Promise refs causing recursion/lockup. Patch to React 19.2.1+ and latest Next.js now. Cloudflare WAF already blocks the DoS ones and is adding rules for others.

    Post summary

    The post discloses three critical CVEs affecting React Server Components and Next.js, details their exploitation vectors, and provides patch guidance along with Cloudflare WAF mitigations.

    00000227
    8.7M followersView on X
CPE platform detail83 entries

83 of 83 entries

PartVendorProductVersionTarget SWTarget HW
Appfacebookreact---
Appvercelnext.js-node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js15.6.0node.js-
Appvercelnext.js16.1.0node.js-
Appvercelnext.js16.1.0node.js-
Appvercelnext.js16.1.0node.js-
Appvercelnext.js16.1.0node.js-
Appvercelnext.js16.1.0node.js-
Appvercelnext.js16.1.0node.js-
Appvercelnext.js16.1.0node.js-
Appvercelnext.js16.1.0node.js-
Appvercelnext.js16.1.0node.js-
Appvercelnext.js16.1.0node.js-
Appvercelnext.js16.1.0node.js-
Appvercelnext.js16.1.0node.js-
Appvercelnext.js16.1.0node.js-
Appvercelnext.js16.1.0node.js-
Appvercelnext.js16.1.0node.js-
Appvercelnext.js16.1.0node.js-
Appvercelnext.js16.1.0node.js-
Appvercelnext.js16.1.0node.js-
Appvercelnext.js16.1.0node.js-
Appvercelnext.js16.1.0node.js-

Explore more