VDB

GCVE-110-NCSC-2025-394

GCVE-110-NCSC-2025-394
Advisory PublishedCVSS 7.5/10
Vulnetix · Advisory published December 12, 2025
The fix for CVE-2025-55184 in React Server Components is incomplete, leaving versions 19.0.2, 19.1.3, and 19.2.2 vulnerable to denial of service attacks due to unsafe deserialization of HTTP request payloads.

Weaknesses (CWE)

CWE-497Exposure of Sensitive System Information to an Unauthorized Control SphereCWE-400Uncontrolled Resource Consumption

Risk Scores

CVSS 3.1
7.5/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersionsPlatforms
Meta Open Sourcevers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›