CVE-2025-55184: React Server Components – Denial of Service

CVE-2025-55184: React Server Components - Denial of Service-渗透云记 - 专注于网络安全与技术分享
CVE-2025-55184: React Server Components – Denial of Service
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2025-55184: React Server Components – Denial of Service

漏洞描述

React Server Components 19.0.0 to 19.2.1 including react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack contain an insecure deserialization vulnerability caused by unsafe payload deserialization in Server Function endpoints, letting unauthenticated attackers cause denial of service by hanging the server process.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享