Two new security vulnerabilities have been discovered in React Server Components affecting Next.js App Router applications. CVE-2025-55184 is a high-severity denial of service vulnerability that can hang server processes through crafted HTTP requests. CVE-2025-55183 is a medium-severity issue that can expose compiled source

3m read timeFrom nextjs.org
Post cover image
Table of contents
ImpactAffected and Fixed Next.js VersionsRequired ActionResourcesDiscovery

Sort: