CVE-2025-55183: Facebook React

Medium severity, CVSS 5.3. EPSS: 64.2% chance of exploitation in the next 30 days.

An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. A specifically crafted HTTP request sent to a vulnerable Server Function may unsafely return the source code of any Server Function. Exploitation requires the existence of a Server Function which explicitly or implicitly exposes a stringified argument.

Affected products

  • Facebook React: from 19.0.0, before 19.0.2 (fixed in 19.0.2); from 19.1.0, before 19.1.3 (fixed in 19.1.3); from 19.2.0, before 19.2.2 (fixed in 19.2.2)
  • Vercel Next.js: from 15.0.0, before 15.0.7 (fixed in 15.0.7); from 15.1.0, before 15.1.11 (fixed in 15.1.11); from 15.2.0, before 15.2.8 (fixed in 15.2.8); from 15.3.0, before 15.3.8 (fixed in 15.3.8); from 15.4.0, before 15.4.10 (fixed in 15.4.10); from 15.5.0, before 15.5.9 (fixed in 15.5.9); …

Published 2025-12-11. Last modified 2026-10-07.