megachangelog
Security19.0.2, 19.1.3, 19.2.2 (React); 14.2.35, 15.0.7, 15.1.11, 15.2.8, 15.3.8, 15.4.10, 15.5.9, 16.0.10 (Next.js)

React Server Components security update: DoS and Source Code Exposure

Two vulnerabilities in React Server Components have been patched: a high-severity Denial of Service attack (CVE-2025-55184) that can hang servers and a medium-severity Source Code Exposure issue (CVE-2025-55183) that can leak compiled source code. All users should upgrade to the latest patched versions of React, Next.js, and affected downstream frameworks immediately.

See the for the latest updates.Security Bulletin

Summary

Impact

Resolution

Fixed in

Credit

References

Two additional vulnerabilities in React Server Components have been identified: a high-severity Denial of Service () and a medium-severity Source Code Exposure (). These issues were discovered while security researchers examined the patches for the original React2Shell vulnerability. The initial fix was incomplete and did not fully prevent denial-of-service attacks for all payload types, resulting in . CVE-2025-55184CVE-2025-55183CVE-2025-67779

Importantly, none of these new issues allow for Remote Code Execution.

We created new rules to address these vulnerabilities and deployed them to the Vercel WAF to automatically protect all projects hosted on Vercel at no cost. However, do not rely on the WAF for full protection. Immediate upgrades to a patched version are required.

A malicious HTTP request can be crafted and sent to any App Router endpoint that, when deserialized, can cause the server process to hang and consume CPU.

A malicious HTTP request can be crafted and sent to any App Router endpoint that can return the compiled source code of Server Actions. This could reveal business logic, but would not expose secrets unless they were hardcoded directly into Server Action's code.

These vulnerabilities are present in versions , , , , , , and of the following packages:19.0.019.0.119.1.019.1.119.1.219.2.019.2.1

These packages are included in the following frameworks and bundlers:

After creating mitigations to address these vulnerabilities, we deployed them across our globally-distributed platform to protect our customers. We still recommend upgrading to the latest patched version.

Updated releases of React and affected downstream frameworks include fixes to prevent these issues. All users should upgrade to a patched version as soon as possible.

Frameworks and bundlers using the aforementioned packages should install the latest versions provided by their respective maintainers.

Thanks to from GMO Flatt Security Inc. and for identifying and responsibly reporting these vulnerabilities, and the Meta Security and React teams for their partnership.RyotaKAndrew MacPherson

Read more

Denial of Service ()CVE-2025-55184

Source Code Exposure ()CVE-2025-55183

  • react-server-dom-parcel

  • react-server-dom-webpack

  • react-server-dom-turbopack

  • : , , , and .Next.js13.x14.x15.x16.x

  • Other frameworks and plugins that embed or depend on React Server Components implementation (e.g., Vite, Parcel, React Router, RedwoodSDK, Waku)

  • .React: 19.0.2,19.1.3,19.2.2

  • .Next.js: 14.2.35,15.0.7,15.1.11,15.2.8,15.3.8,15.4.10,15.5.9,15.6.0-canary.60,16.0.10,16.1.0-canary.19

securityreactserver-componentsdossource-code

Source: original entry ↗

More from Vercel

Follow Vercel to get its new changes in your feed and email digest.

Feature

OpenAI Decisions API now available on AI Gateway

OpenAI's Decisions API is now accessible through Vercel's AI Gateway with an OpenAI-compatible endpoint, enabling decision models to answer typed questions and return probabilities, choices, and scores for routing, triage, and guardrails use cases. Support is available across the OpenAI SDK, AI SDK, HTTP API, and CLI with the latest versions.

ai-gatewayopenaiapidecisionssdks
Feature

Timestamp attributes now supported in Vercel Flags

Vercel Flags now supports timestamp attributes for entities, allowing you to create time-based targeting rules. Use this feature to run limited-time campaigns, show content between specific dates, or target users based on registration date.

flagstargetingfeaturetimestampscampaigns
Feature

Glyph Cluster now available in stealth on AI Gateway

Glyph Cluster, a reasoning model for coding and long-context analysis, is now available as a stealth model on Vercel's AI Gateway for Pro and Enterprise plan teams with purchased AI Gateway credits at no cost during the stealth period. The model supports function calling, streams responses, and can be accessed via AI SDK, OpenAI-compatible APIs, and coding agents.

ai-gatewaymodelscodingstealth
See all Vercel changes →