React Server Components have two new security vulnerabilities: a high-severity Denial of Service (CVE-2025-55184) that can hang servers through malicious HTTP requests, and a medium-severity Source Code Exposure (CVE-2025-55183) that can leak Server Function source code. These affect React versions 19.0.0 through 19.2.1 and frameworks like Next.js, React Router, and Waku. Fixes are available in versions 19.0.2, 19.1.3, and 19.2.2. Apps not using React Server Components or server-side rendering are unaffected. Immediate upgrade is recommended despite hosting provider mitigations being in place.
Table of contents
Immediate Action RequiredHigh Severity: Denial of ServiceMedium Severity: Source Code ExposureTimelineAttributionSort: