CVE-2025-55184 is a denial-of-service vulnerability in React Server Components stemming from unsafe handling of the React Flight protocol deserialization layer. An attacker can send a malformed RSC request to trigger an infinite loop or hung server state, taking the app offline without needing code execution. The flaw is

4m read timeFrom aikido.dev
Post cover image
Table of contents
Key TakeawaysTL;DR: Are You Still at Risk?Remediation StepsBackgroundDeep DiveWho Is Affected?SeverityTimelineScan Your Codebase Now

Sort: