React Server Components have two new security vulnerabilities: a high-severity Denial of Service (CVE-2025-55184) that can hang servers through malicious HTTP requests, and a medium-severity Source Code Exposure (CVE-2025-55183) that can leak Server Function source code. These affect React versions 19.0.0 through 19.2.1 and
•4m read time• From react.dev
Table of contents
Immediate Action RequiredHigh Severity: Denial of ServiceMedium Severity: Source Code ExposureTimelineAttributionSort: