Deserialization of Untrusted Data in React - CVE-2025-67779

 

Deserialization of Untrusted Data in React - CVE-2025-67779

Published: December 12, 2025


Vulnerability identifier: #VU119893
CSH Severity: Medium
CVSS v4 BT: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2025-67779
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to insecure input validation when processing serialized data. A remote attacker can send a specially crafted HTTP request, which can cause an infinite loop and prevent future HTTP requests from being served, leading to a denial of service condition. 

The vulnerability affects the following components:

- react-server-dom-webpack (Meta) 
- react-server-dom-turbopack (Meta) 
- react-server-dom-parcel (Meta) 


Affected software

React
QRadar Pre-Validation App
QRadar User Behavior Analytics
Next.js
IBM Security QRadar Analyst Workflow

How to mitigate CVE-2025-67779

Install updates from vendor's website.

React - addressed in versions 19.0.3, 19.1.4, 19.2.3
QRadar Pre-Validation App - update to 2.0.2
QRadar User Behavior Analytics - update to 5.0.3
Next.js - addressed in versions 14.2.35, 15.0.7, 15.1.11, 15.2.8, 15.3.8, 15.4.10, 15.5.9, 16.0.10
IBM Security QRadar Analyst Workflow - update to 3.0.1

External References

Related Security Bulletins