VDB
GCVE-110-NCSC-2025-394
GCVE-110-NCSC-2025-394
Advisory PublishedCVSS 7.5/10
The fix for CVE-2025-55184 in React Server Components is incomplete, leaving versions 19.0.2, 19.1.3, and 19.2.2 vulnerable to denial of service attacks due to unsafe deserialization of HTTP request payloads.
Weaknesses (CWE)
CWE-497Exposure of Sensitive System Information to an Unauthorized Control SphereCWE-400Uncontrolled Resource Consumption
Risk Scores
CVSS 3.1
7.5/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Meta Open Source | vers:unknown/* | — | — |
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.