CVE-2025-55184 is a denial-of-service vulnerability in React Server Components stemming from unsafe handling of the React Flight protocol deserialization layer. An attacker can send a malformed RSC request to trigger an infinite loop or hung server state, taking the app offline without needing code execution. The flaw is
Table of contents
Key TakeawaysTL;DR: Are You Still at Risk?Remediation StepsBackgroundDeep DiveWho Is Affected?SeverityTimelineScan Your Codebase NowSort: