CVE-2025-67779

HIGHCVSS 7.5/10EPSS 18.88%

Last modified

CVE-2025-67779 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe deserialization of payloads from HTTP requests to Server Function endpoints. EPSS estimates a 18.88% chance of exploitation in the next 30 days.

Description

It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe deserialization of payloads from HTTP requests to Server Function endpoints. This can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
18.88%

96.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
FacebookReact19.0.2
FacebookReact19.1.3
FacebookReact19.2.2
VercelNext.Js>= 13.3.0, < 14.2.35
VercelNext.Js>= 15.0.0, < 15.0.7
VercelNext.Js>= 15.1.0, < 15.1.11
VercelNext.Js>= 15.2.0, < 15.2.8
VercelNext.Js>= 15.3.0, < 15.3.8
VercelNext.Js>= 15.4.0, < 15.4.10
VercelNext.Js>= 15.5.0, < 15.5.9
VercelNext.Js>= 16.0.0, < 16.0.10
VercelNext.Js15.6.0
VercelNext.Js16.1.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2025-67779?
It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe deserialization of payloads from HTTP requests to Server Function endpoints. This can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served.
How severe is CVE-2025-67779?
CVE-2025-67779 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 18.88% probability of exploitation in the next 30 days.
How do I fix CVE-2025-67779?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2025-67779?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST