
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67779 is a Denial of Service (DoS) vulnerability in React Server Components resulting from an incomplete fix for CVE-2025-55184. Disclosed on December 12, 2025, it affects react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack at versions 19.0.2, 19.1.3, and 19.2.2, as well as multiple Next.js versions from 13.3.0 through 16.x. The flaw allows unsafe deserialization of HTTP request payloads sent to Server Function endpoints, triggering an infinite loop that hangs the server process. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Meta Advisory).
The root cause is classified under CWE-502 (Deserialization of Untrusted Data) and CWE-400 (Uncontrolled Resource Consumption). The prior patch for CVE-2025-55184 failed to account for a specific edge case in the deserialization logic of React Server Components' Server Function endpoints, allowing a crafted HTTP request payload to trigger an infinite loop in the server process. No authentication, privileges, or user interaction are required — the attack vector is fully network-accessible with low complexity. A PoC repository targeting both CVE-2025-55184 and CVE-2025-67779 has been published publicly (GitHub Advisory, GitHub PoC).
Successful exploitation causes the server process to enter an infinite loop, effectively hanging it and preventing any future HTTP requests from being served — a complete availability loss. The impact is limited to availability (no confidentiality or integrity impact), but a single unauthenticated request can render an entire Node.js server instance unresponsive. Applications using React Server Components with server-side rendering frameworks such as Next.js are at risk; apps that do not use a server or do not use a framework supporting React Server Components are not affected (GitHub Advisory, react.dev Blog).
A public PoC repository targeting CVE-2025-55184 and CVE-2025-67779 together has been published on GitHub (GitHub PoC). The EPSS score is approximately 1.646% (82nd percentile), indicating a meaningful probability of exploitation within 30 days relative to other CVEs (GitHub Advisory). The broader React Server Components vulnerability cluster (including the related CVE-2025-55182 "React2Shell") has seen active in-the-wild exploitation by nation-state threat actors including Chinese and Iranian groups, with Google identifying five Chinese APT groups leveraging related RSC flaws (SecurityWeek, The Register). CVE-2025-67779 itself has not been added to the CISA KEV catalog as of available data.
/_next/action or similar RSC action routes) with anomalous or oversized payloads from unexpected source IPs.Upgrade immediately to the patched versions: react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack versions 19.0.3, 19.1.4, or 19.2.3. For Next.js, upgrade to the corresponding fixed releases (14.2.35, 15.0.7, 15.1.11, 15.2.8, 15.3.8, 15.4.10, 15.5.9, or 16.0.10 and later). Applications that do not use a server or do not use a framework/bundler supporting React Server Components are not affected and require no action. As a temporary network-level mitigation, consider rate-limiting or blocking unexpected POST requests to Server Function endpoints at the WAF or load balancer layer (GitHub Advisory, react.dev Blog, Vercel Changelog).
Meta/React published an official blog post and security advisory on December 11–12, 2025, urging immediate upgrades and noting the incomplete nature of the prior CVE-2025-55184 fix (react.dev Blog, Meta Advisory). Vercel issued a security bulletin and changelog entry covering the RSC vulnerability cluster (Vercel Changelog). The broader React2Shell vulnerability cluster attracted significant media coverage from The Hacker News, The Register, Cybersecurity Dive, and others, with Cloudflare publishing a threat brief on RSC exploitation (Cloudflare Blog). The Canadian Centre for Cyber Security issued advisory AV25-834 covering the React RSC vulnerabilities (CCCS Advisory). Community sentiment on social media (Bluesky, Mastodon, LinkedIn) reflected urgency around patching, particularly given the proximity to the holiday season and the active exploitation of related RSC flaws.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."