📦 React

by Facebook

🔍 What is React?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-55182

CRITICAL CVSS 10.0 Dec 3, 2025

A critical pre-authentication remote code execution vulnerability exists in React Server Components where unsafe deserialization of HTTP payloads allows attackers to execute arbitrary code without aut...

CVE-2026-23864

HIGH CVSS 7.5 Jan 26, 2026

Multiple denial of service vulnerabilities in React Server Components allow attackers to crash servers or cause resource exhaustion by sending specially crafted HTTP requests to Server Function endpoi...

CVE-2025-67779

HIGH CVSS 7.5 Dec 12, 2025

This vulnerability allows attackers to send specially crafted HTTP requests to React Server Components Server Function endpoints, causing unsafe deserialization that triggers an infinite loop. This le...

CVE-2025-55184

HIGH CVSS 7.5 Dec 11, 2025

A pre-authentication denial of service vulnerability in React Server Components allows attackers to send specially crafted HTTP requests to Server Function endpoints, causing infinite loops that hang ...

CVE-2025-55183

MEDIUM CVSS 5.3 Dec 11, 2025

An information leak vulnerability in React Server Components allows attackers to retrieve source code of Server Functions via crafted HTTP requests. This affects React Server Components versions 19.0....