← Vulnerability feed

Vulnerability record · CVE-2025-55183 · published 11 December 2025

CVE-2025-55183: React Server Components source code leak via crafted HTTP request

Vercel · Next.Js

React Server Components versions 19.0.0 through 19.2.1 (react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack) can return the source code of Server Functions when a specially crafted HTTP request hits a vulnerable Server Function. It matters because server-side source code can expose logic, secrets and internal endpoints, and the affected packages are widely used in Next.js and React applications. Exploitation requires a Server Function that explicitly or implicitly exposes a stringified argument.

5.3 CVSS 3.1 Medium EPSS 64% · top 0.8%
5.3CVSS 3.1 base score
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. A specifically crafted HTTP request sent to a vulnerable Server Function may unsafely return the source code of any Server Function. Exploitation requires the existence of a Server Function which explicitly or implicitly exposes a stringified argument.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityCVSS is only Medium (5.3) but EPSS is 0.64233 at the 99.19th percentile and the vendor advisory is tagged Exploit, so active exploitation is likely.

What it is

React Server Components versions 19.0.0 through 19.2.1 (react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack) can return the source code of Server Functions when a specially crafted HTTP request hits a vulnerable Server Function. It matters because server-side source code can expose logic, secrets and internal endpoints, and the affected packages are widely used in Next.js and React applications. Exploitation requires a Server Function that explicitly or implicitly exposes a stringified argument.

Impact

An unauthenticated attacker can read the source code of Server Functions, potentially revealing business logic, embedded secrets and internal API details. The CVSS confidentiality impact is Low, so the direct data exposure is limited but still useful for follow-on attacks.

Attack surface

Reached over the network via a crafted HTTP request to a Server Function endpoint; the CVSS vector shows no privileges and no user interaction required. The flaw only triggers when a Server Function exposes a stringified argument, so not every deployment is reachable.

Exploitation

Not listed in CISA KEV, but EPSS is 0.64233 (99.19th percentile), indicating high predicted exploitation activity. The vendor advisory is tagged Exploit, so public exploitation detail exists.

What to do

  • Upgrade React Server Components packages (react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack) and Next.js to versions patched for CVE-2025-55183.
  • Audit Server Functions for arguments that are explicitly or implicitly stringified and remove or restrict that exposure.
  • Apply network controls or WAF rules to block crafted requests targeting Server Function endpoints until patching is complete.
  • Rotate any secrets or credentials that may have been embedded in server-side source code.
  • Monitor vendor advisories from React and Meta for updated guidance.

Detection

  • Inspect HTTP request logs for unusual or malformed requests to Server Function endpoints that return source-like content.
  • Alert on responses containing server-side source code patterns (import statements, function bodies) from Server Function routes.
  • Review Server Function definitions for stringified arguments and flag them for remediation tracking.
  • Correlate outbound or anomalous access to Server Function endpoints with the EPSS-elevated exploitation window.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-55183 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-55182React Server Components pre-auth deserialization RCEReact Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 (react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack) u…KEVEPSS 100%analysed9.1CVE-2025-29927Next.js middleware authorization bypass via x-middleware-subrequest headerNext.js versions from 1.11.4 up to (but not including) 12.3.5, 13.5.9, 14.2.25, and 15.2.3 allow authorization checks performed in middleware to be b…EPSS 99%analysed8.6CVE-2026-44578Vercel next.js server-side request forgery (ssrf) vulnerabilityNext.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the …EPSS 1.9%8.3CVE-2026-64649Vercel next.js server-side request forgery (ssrf) vulnerabilityNext.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server A…EPSS 0.46%8.3CVE-2026-64642Vercel next.js improper authorization vulnerabilityNext.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applica…EPSS 0.64%8.3CVE-2026-64645Vercel next.js open redirect vulnerabilityNext.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or…EPSS 0.41%8.2CVE-2026-64641Vercel next.js vulnerabilityNext.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted request…EPSS 0.86%8.2CVE-2025-57822Vercel next.js server-side request forgery (ssrf) vulnerabilityNext.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next() was used without explicitly …EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2025-55183), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.