Looking for the vulnerability index of Invicti's legacy products?
Next.js Deserialization of Untrusted Data Vulnerability - CVE-2025-55184 - Vulnerability Database

Next.js Deserialization of Untrusted Data Vulnerability - CVE-2025-55184

High
Reference: CVE-2025-55184
Title: Next.js Deserialization of Untrusted Data Vulnerability
Overview:

A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0 19.0.1 19.1.0 19.1.1 19.1.2 19.2.0 and 19.2.1 including the following packages: react-server-dom-parcel react-server-dom-turbopack and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints which can cause an infinite loop that hangs the server process and may prevent future HTTP requests from being served.