shipfeedAI news, curated daily

00:32:39 CET
21 MAY00:32:39shipfeed
pull to refreshlast sync
Just in — 30 new
§ feed · storyline

React Server Components security update: DoS and Source Code Exposure

React Server Components patches two new CVEs — a high-severity denial-of-service flaw and a medium-severity source code exposure — affecting versions 19.0.0 through 19.2.1, with immediate upgrades required.

Dec 11 · · primary fetch1 sourceupdated Dec 11 ·

See the for the latest updates.Security Bulletin Summary Impact Resolution Fixed in Credit References Two additional vulnerabilities in React Server Components have been identified: a high-severity Denial of Service () and a medium-severity Source Code Exposure (). These issues were discovered while security researchers examined the patches for the original React2Shell vulnerability. The initial fix was incomplete and did not fully prevent denial-of-service attacks for all payload types, resulting in . CVE-2025-55184CVE-2025-55183CVE-2025-67779 Importantly, none of these new issues allow for Remote Code Execution.

We created new rules to address these vulnerabilities and deployed them to the Vercel WAF to automatically protect all projects hosted on Vercel at no cost. However, do not rely on the WAF for full protection. Immediate upgrades to a patched version are required. A malicious HTTP request can be crafted and sent to any App Router endpoint that, when deserialized, can cause the server process to hang and consume CPU. A malicious HTTP request can be crafted and sent to any App Router endpoint that can return the compiled source code of Server Actions. This could reveal…

read full article on vercel.com
§ sources1 publication · timeline below
  1. vercel.comReact Server Components security update: DoS and Source Code Exposureprimary