PT-2025-50722 · Unknown+1 · React-Server-Dom-Turbopack+3

Published

2025-12-11

·

Updated

2026-02-26

·

CVE-2025-55183

CVSS v3.1
5.3
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions React versions 19.0.0 through 19.2.1 react-server-dom-parcel versions 19.0.0 through 19.2.1 react-server-dom-turbopack versions 19.0.0 through 19.2.1 react-server-dom-webpack versions 19.0.0 through 19.2.1
Description An information leak issue exists in React Server Components. A crafted HTTP request to a vulnerable Server Function can expose the source code of that function. This requires the Server Function to expose a stringified argument. The issue affects applications using React Server Components, potentially impacting a large number of deployments. The vulnerability could lead to the disclosure of business logic and potentially sensitive information.
Recommendations Update to a newer version of React that contains a fix for this vulnerability.

Fix

Related Identifiers

CVE-2025-55183
GHSA-925W-6V3X-G4J4

Affected Products

React
React-Server-Dom-Parcel
React-Server-Dom-Turbopack
React-Server-Dom-Webpack