Deserialization of Untrusted Data in React - CVE-2025-67779
Published: December 12, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to insecure input validation when processing serialized data. A remote attacker can send a specially crafted HTTP request, which can cause an infinite loop and prevent future HTTP requests from being served, leading to a denial of service condition.
The vulnerability affects the following components:
- react-server-dom-webpack (Meta)
- react-server-dom-turbopack (Meta)
- react-server-dom-parcel (Meta)
Affected software
QRadar Pre-Validation App
QRadar User Behavior Analytics
Next.js
IBM Security QRadar Analyst Workflow
How to mitigate CVE-2025-67779
QRadar Pre-Validation App - update to 2.0.2
QRadar User Behavior Analytics - update to 5.0.3
Next.js - addressed in versions 14.2.35, 15.0.7, 15.1.11, 15.2.8, 15.3.8, 15.4.10, 15.5.9, 16.0.10
IBM Security QRadar Analyst Workflow - update to 3.0.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Facebook React
- Denial of service in Next.js React Server Components
- Multiple vulnerabilities in IBM Security QRadar Analyst Workflow for IBM QRadar SIEM
- Multiple vulnerabilities in IBM QRadar User Behavior Analytics
- Multiple vulnerabilities in IBM QRadar Pre-Validation App