React & Next.js DoS Vulnerability (CVE-2025-55184): What You Need to Fix After React2Shell
aikido.dev | vulnerability | High | CVE-2025-55184 | #appsec | #vulnerability-research | #denial-of-service | #deserialization | #react2shell | #nextjs | #react | #dos | #cve-2025-55184 | #rsc
Summary
CVE-2025-55184 is a DoS flaw in React Server Components tied to the same Flight deserialization layer as React2Shell; crafted requests hang servers, and teams must also patch follow-up CVE-2025-67779.
- CVSS
- 7.5
- Published
- Collected
Skip to content