Wallarm API Security Wallarm updates logo

Wallarm updates

Discover the latest features, improvements, and updates in Wallarm API Security

Subscribe to Updates

Labels

  • All Posts
  • API Security
  • WAAP
  • ANNOUNCEMENT
  • Security Edge
  • IMPROVEMENT
  • FIX
  • Security Testing

Jump to Month

  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • March 2022
  • February 2022
  • December 2021
  • November 2021
  • October 2021
  • August 2021
  • April 2021
  • March 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • December 2019
  • October 2019
  • August 2019
  • April 2019
API Security
2 days ago

React Server Components: New Vulnerabilities and Virtual Patch

In addition to the vulnerabilities previously published, React has disclosed new vulnerabilities affecting applications using React Server Components.

  • Denial of Service (DoS) — High severity, CVSS 7.5
     CVE-2025-55184, CVE-2025-67779: Crafted requests can exhaust server resources, causing hangs or service unavailability.

  • Source Code Exposure — Medium severity, CVSS 5.3
     CVE-2025-55183: Specially formed requests may lead to disclosure of server-side source code

These issues affect the same React Server Components request handling surface as React2Shell (CVE-2025-55182) but do not enable remote code execution. The previously released React2Shell fixes continue to prevent RCE, while these new vulnerabilities impact availability and confidentiality.

Recommendations:
Upgrade to the latest patched React versions and review the exposure of React Server Components endpoints.

Wallarm mitigation:
To protect customers who aren’t using blocking mode across all apps and APIs, Wallarm has rolled out a virtual patch that blocks exploitation regardless of whether customers use blocking or monitoring mode. Please contact support if you’d like to opt out.

Avatar of authorWallarm team