CVE-2025-67779 is a high-severity denial of service vulnerability in React Server Components, affecting versions 19.0.2, 19.1.3, and 19.2.2, including products like Next.js. It stems from an incomplete fix for a prior vulnerability, allowing unsafe deserialization of HTTP request payloads. This can trigger an infinite loop, causing the server process to hang and preventing it from serving future requests. Rated 7.5 HIGH, it is exploitable over the network with low complexity and no user interaction, primarily impacting system availability. Although specific public exploit code is not detailed, this CVE is on the "Hot List: Active" and is part of a broader set of React Server Component vulnerabilities currently experiencing active exploitation and significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
19.0.2CPE matchmatch criteria | cpe:2.3:a:facebook:react:19.0.2:*:*:*:*:*:*:* | ||
19.1.3CPE matchmatch criteria | cpe:2.3:a:facebook:react:19.1.3:*:*:*:*:*:*:* | ||
19.2.2CPE matchmatch criteria | cpe:2.3:a:facebook:react:19.2.2:*:*:*:*:*:*:* | ||
>= 13.3.0, < 14.2.35CPE matchmatch criteria | cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:* | ||
>= 15.0.0, < 15.0.7CPE matchmatch criteria | cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.