A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints, which can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served.
https://socket.dev/blog/nextjs-moves-to-scheduled-security-releases
https://cyberscoop.com/react2shell-vulnerability-fallout-spreads/
https://www.theregister.com/2025/12/15/react2shell_flaw_china_iran/
https://www.databreachtoday.com/nation-state-cybercrime-exploits-tied-to-react2shell-a-30285
https://www.theregister.com/2025/12/12/new_react_secretleak_bugs/
https://thehackernews.com/2025/12/new-react-rsc-vulnerabilities-enable.html
https://github.com/Neverland-lcl/Security_OS_CVE
https://github.com/Neverland-lcl/Security_OS
https://github.com/lvx9101-ux/CVE-2025-55182
https://github.com/Theori-lO/reactguard
https://github.com/devianntsec/CVE-2025-55182
https://github.com/JSH-data/CVE-2025-55184_CVE-2025-67779
https://github.com/yogeshkumar09/yogeshkumar09.github.io
https://github.com/yogeshkumar09/CVE-2025-55184_Testing
https://github.com/DebaA17/CVE-scanner-cli
https://github.com/yourpwnguy/cveye
https://github.com/dbwlsdnr95/CVE-2025-55182-React2Shell-Nextjs-RSC-Analysis
https://github.com/shubham-01-star/OpsGuard-simulation
https://github.com/pnndrs/react-rsc-cve-scanner
https://github.com/MammaniNelsonD/React2P4IM0Nshell
https://github.com/KkHackingLearning/CVE-2025-55184_Testing
https://github.com/Kajal5414/CVE-2025-55184_Testing
https://github.com/abdozkaya/rsc-security-auditor
https://github.com/StealthMoud/react-server-cve-lab
https://github.com/asg5704/check-cve
https://github.com/caohungphu/react2shell
https://github.com/williavs/nextjs-security-update
https://github.com/hans362/CVE-2025-55184-poc
https://github.com/theori-io/reactguard
https://github.com/hlsitechio/shellockolm
https://github.com/hlsitechio/Shellockolm-AI-CLI-MCP-Scanner
https://github.com/nxgn-kd01/react2shell-scanner
Published: 2025-12-11
Updated: 2025-12-15
Base Score: 7.8
Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C
Severity: High
Base Score: 7.5
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity: High
EPSS: 0.66882
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability Being Monitored