Information disclosure in React - CVE-2025-55183
Published: December 12, 2025 / Updated: January 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the server may expose the source code of any server function when receiving a specially crafted HTTP request. A remote attacker can gain access to sensitive information.
The vulnerability affects the following components:
- react-server-dom-webpack (Meta)
- react-server-dom-turbopack (Meta)
- react-server-dom-parcel (Meta)
Successful exploitation requires the existence of a Server Function which explicitly or implicitly exposes a stringified argument.
Affected software
QRadar Pre-Validation App
QRadar User Behavior Analytics
Next.js
IBM Security QRadar Analyst Workflow
How to mitigate CVE-2025-55183
QRadar Pre-Validation App - update to 2.0.2
QRadar User Behavior Analytics - update to 5.0.3
Next.js - addressed in versions 15.0.6, 15.1.10, 15.2.7, 15.3.7, 15.4.9, 15.5.8, 16.0.9
IBM Security QRadar Analyst Workflow - update to 3.0.1