PT-2025-50775 · Meta · React Server Components

Published

2025-12-11

·

Updated

2026-01-22

·

CVE-2025-67779

CVSS v3.1
7.5
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions React versions 19.0.2 through 19.2.2
Description An incomplete fix for a previous issue allows for a denial of service attack in React Server Components. Specifically, unsafe deserialization of payloads from HTTP requests to Server Function endpoints can cause an infinite loop, potentially hanging the server process and preventing it from serving future requests. This issue affects servers utilizing React Server Components. The issue can be triggered by certain payload shapes.
Recommendations React versions 19.0.2 through 19.1.3 should be updated to version 19.2.3. React version 19.2.2 should be updated to version 19.2.3.

Fix

DoS

Resource Exhaustion

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-67779

Affected Products

React Server Components