CVE-2025-67779
HIGHDescription
It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe deserialization of payloads from HTTP requests to Server Function endpoints. This can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| react | |
| react | |
| react | |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
References
Frequently Asked Questions
What is CVE-2025-67779? +
How severe is CVE-2025-67779? +
What products are affected by CVE-2025-67779? +
How do I check if I'm vulnerable to CVE-2025-67779? +
Related Vulnerabilities
Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension types …
SEPPmail Secure Email Gateway before version 15.0.4 insecurely deserializes untrusted data, which can be reached from the new GINA UI …
RELATE is a web-based courseware package. Prior to commit d66ba5659b459bf1ba56b7109b5f9ecf197cbefb, RELATE LMS configures its Celery workers to accept and deserialize …
A security vulnerability has been identified in the IBL Software Engineering Visual Weather and derived products (NAMIS, Aero Weather, Satellite …
PixelYourSite - Your smart PIXEL (TAG) and API Manager 10.1.1.1 was found to be vulnerable. Unvalidated user input is used …
The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through …