Deno
Read post

React / Next.js Denial-of-Service Vulnerability: Deno Deploy users protected

A high severity DoS vulnerability (CVE-2025-55184) has been discovered in React Server Components and Next.js that allows attackers to hang servers through crafted HTTP requests causing infinite loops. The vulnerability affects Next.js 13.3+, 14, 15, and 16 using App Router, as well as applications using React Router RSC, Waku, Parcel RSC, Vite RSC, and RedwoodSDK. Deno Deploy has implemented runtime-level mitigations to protect hosted applications automatically. All other users must immediately upgrade to patched versions: Next.js 16.0.9+, 15.5.8+, or 14.2.34+, and React Server Components libraries to 19.2.2+. This is separate from the previously disclosed RCE vulnerability and requires a new upgrade.

    #security#webdev#react#nextjs#deno
Dec 11, 2025•4m read time•From deno.com
Post cover image
34 Impressions
Deno's image
Deno

Deno's official blog provides updates, tutorials, and use cases for Deno, a secure JavaScript/TypeSc...

547 Followers

•

2.2K Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard