Vulnerability record · CVE-2025-55183 · published 11 December 2025
CVE-2025-55183: React Server Components source code leak via crafted HTTP request
Vercel · Next.Js
React Server Components versions 19.0.0 through 19.2.1 (react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack) can return the source code of Server Functions when a specially crafted HTTP request hits a vulnerable Server Function. It matters because server-side source code can expose logic, secrets and internal endpoints, and the affected packages are widely used in Next.js and React applications. Exploitation requires a Server Function that explicitly or implicitly exposes a stringified argument.
Description
An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. A specifically crafted HTTP request sent to a vulnerable Server Function may unsafely return the source code of any Server Function. Exploitation requires the existence of a Server Function which explicitly or implicitly exposes a stringified argument.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Automated analysis
high priorityCVSS is only Medium (5.3) but EPSS is 0.64233 at the 99.19th percentile and the vendor advisory is tagged Exploit, so active exploitation is likely.
What it is
React Server Components versions 19.0.0 through 19.2.1 (react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack) can return the source code of Server Functions when a specially crafted HTTP request hits a vulnerable Server Function. It matters because server-side source code can expose logic, secrets and internal endpoints, and the affected packages are widely used in Next.js and React applications. Exploitation requires a Server Function that explicitly or implicitly exposes a stringified argument.
Impact
An unauthenticated attacker can read the source code of Server Functions, potentially revealing business logic, embedded secrets and internal API details. The CVSS confidentiality impact is Low, so the direct data exposure is limited but still useful for follow-on attacks.
Attack surface
Reached over the network via a crafted HTTP request to a Server Function endpoint; the CVSS vector shows no privileges and no user interaction required. The flaw only triggers when a Server Function exposes a stringified argument, so not every deployment is reachable.
Exploitation
Not listed in CISA KEV, but EPSS is 0.64233 (99.19th percentile), indicating high predicted exploitation activity. The vendor advisory is tagged Exploit, so public exploitation detail exists.
What to do
- Upgrade React Server Components packages (react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack) and Next.js to versions patched for CVE-2025-55183.
- Audit Server Functions for arguments that are explicitly or implicitly stringified and remove or restrict that exposure.
- Apply network controls or WAF rules to block crafted requests targeting Server Function endpoints until patching is complete.
- Rotate any secrets or credentials that may have been embedded in server-side source code.
- Monitor vendor advisories from React and Meta for updated guidance.
Detection
- Inspect HTTP request logs for unusual or malformed requests to Server Function endpoints that return source-like content.
- Alert on responses containing server-side source code patterns (import statements, function bodies) from Server Function routes.
- Review Server Function definitions for stringified arguments and flag them for remediation tracking.
- Correlate outbound or anomalous access to Server Function endpoints with the EPSS-elevated exploitation window.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components | ExploitVendor Advisory |
| https://www.facebook.com/security/advisories/cve-2025-55183 | Vendor Advisory |
Track CVE-2025-55183 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-55183), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.