React maintainers have released patches addressing two newly discovered vulnerabilities that could allow attackers to crash servers via denial-of-service (DoS) attacks and potentially disclose sensitive source code. These flaws, which follow closely after the React2Shell incident, have raised concerns about the security of applications built with React, especially those exposed to untrusted input or running in server-side environments. The vulnerabilities are tracked as CVE-2025-55183, CVE-2025-55184, and CVE-2025-67779, and security researchers urge immediate attention and patching to mitigate exploitation risks.
Security experts highlight that the vulnerabilities could be exploited to disrupt services or leak proprietary code, posing significant risks to organizations relying on React for web application development. The issues have been acknowledged by both the React development team and independent security researchers, with proof-of-concept details and technical advisories made available to the public. Organizations are advised to review their deployments and apply the latest security updates to prevent potential attacks leveraging these flaws.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
React released patches to address the newly discovered vulnerabilities after their discovery. The fixes were intended to mitigate risks including server-crashing denial-of-service attacks and possible source code disclosure in affected applications.
Three React vulnerabilities, tracked as CVE-2025-55183, CVE-2025-55184, and CVE-2025-67779, were publicly disclosed. Reporting said the issues could enable denial-of-service, source code disclosure, and broader application or supply-chain security risks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.