¡¾·ì϶¹«¸æ¡¿React Server Components »Ø¾ø·þÎñ·ì϶(CVE-2025-55184)

°ä²¼¹¦·ò 2025-12-12

Ò»¡¢·ì϶¸ÅÊö


·ìϼûû³Æ

React Server Components »Ø¾ø·þÎñ·ì϶

CVE   ID

CVE-2025-55184

·ì϶ÀàÐÍ

DOS

·¢ÏÖ¹¦·ò

2025-12-12

·ì϶ÆÀ·Ö

7.5

·ì϶µÈ¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ÀûÓÃÄѶÈ

µÍ

Óû§½»»¥

²»±ØÒª

PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


ReactÊÇÒ»¸öÓÃÓÚ¹¹½¨Óû§½çÃæµÄJavaScript¿â£¬£¬£¬£¬£¬£¬ÓÉFacebook¿ª·¢ºÍÊØ»¤¡£¡£¡£¡£¡£¡£¡£Ëü»ùÓÚ×é¼þ»¯µÄ¿ª·¢Ä£Ê½£¬£¬£¬£¬£¬£¬Í¨¹ýÉêÃ÷ʽ±à³Ì¼ò»¯Á˽çÃæµÄ¹¹½¨ºÍ¸üС£¡£¡£¡£¡£¡£¡£Reactͨ¹ýÐé¹¹DOMÌáÉýäÖȾ»úÄÜ£¬£¬£¬£¬£¬£¬È·±£×îÓ×»¯¶ÔÕæÊµDOMµÄ²Ù×÷£¬£¬£¬£¬£¬£¬ÓÅ»¯ÁËÀûÓõÄÏìÓ¦ËÙ¶È¡£¡£¡£¡£¡£¡£¡£ËüÖ§³Öµ¥ÏòÊý¾ÝÁ÷£¬£¬£¬£¬£¬£¬ÌáÉýÁËÀûÓõĿÉÔ¤²âÐԺͿÉÊØ»¤ÐÔ¡£¡£¡£¡£¡£¡£¡£React¿ÉÓëÆäËû¿â»ò¿ò¼Üһ·ʹÓ㬣¬£¬£¬£¬£¬³£¼ûµÄ×éºÏÔ̺¬React RouterÓÃÓÚ·ÓÉÖÎÀíºÍReduxÓÃÓÚ״̬ÖÎÀí¡£¡£¡£¡£¡£¡£¡£ReactºÏÓÃÓÚ¹¹½¨ÏÖ´úWebºÍÒÆ¶¯¶ËÀûÓ㬣¬£¬£¬£¬£¬¿í·ºÀûÓÃÓÚǰ¶Ë¿ª·¢ÁìÓò¡£¡£¡£¡£¡£¡£¡£


2025Äê12ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬8827Ì«Ñô¼¯Íż¯ÍÅVSRC¼à²âµ½React Server Components´æÔÚ¶à¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬Ô̺¬React Server Components »Ø¾ø·þÎñ·ì϶(CVE-2025-55184)¡¢React Server Components »Ø¾ø·þÎñ·ì϶(CVE-2025-67779)¡¢React Server Components Ô´´úÂë¶¶Âí½Å(CVE-2025-55183)£¬£¬£¬£¬£¬£¬ÆäÖÐCVE-2025-55184ÊÇÒ»¸ö¸ßΣ»Ø¾ø·þÎñ£¨DoS£©·ì϶£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ý¶ñÒâ»ú¹ØµÄHTTPÒªÇ󣬣¬£¬£¬£¬£¬·¢ËÍÖÁReact Server Function¶Ëµã£¬£¬£¬£¬£¬£¬µ¼Ö·´ÐòÁл¯¹ý³ÌÖеÄÎÞÏÞÑ­»·£¬£¬£¬£¬£¬£¬´Ó¶ø¿÷Ëð´óÁ¿CPU×ÊÔ´£¬£¬£¬£¬£¬£¬Ôì³É·þÎñ²»³ÉÓᣡ£¡£¡£¡£¡£¡£CVE-2025-67779ÓëCVE-2025-55184ÓйØ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓöñÒâHTTPÒªÇó´¥·¢ÎÞÏÞÑ­»·£¬£¬£¬£¬£¬£¬µ¼Ö·þÎñÆ÷×ÊÔ´¿÷Ëð´ù¾¡²¢Ê¹·þÎñÖжϡ£¡£¡£¡£¡£¡£¡£CVE-2025-55183ÊÇÒ»¸öÖÐΣԴ´úÂë¶¶Âí½Å£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ý¶ñÒâHTTPÒªÇó¿ÉÄܵ¼ÖÂReact Server ComponentsÖеķþÎñÆ÷¶Ëº¯Êýй¶Դ´úÂ룬£¬£¬£¬£¬£¬Â¶³öÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬£¬ÈçÓ²±àÂëµÄÊý¾Ý¿âÏνÓÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£


¶þ¡¢Ó°ÏìÁìÓò


react-server-dom-webpack¡¢react-server-dom-parcel¡¢react-server-dom-turbopack = 19.0.0¡¢19.0.1¡¢19.0.2

react-server-dom-webpack¡¢react-server-dom-parcel¡¢react-server-dom-turbopack = 19.1.0¡¢19.1.1¡¢19.1.2¡¢19.1.2
react-server-dom-webpack¡¢react-server-dom-parcel¡¢react-server-dom-turbopack = 19.2.0¡¢19.2.1¡¢19.2.2
ÆäËûÊÜÓ°Ïì¿ò¼ÜºÍ´ò°ü·¨Ê½
Next.js <= 15.0.0
React Router ²»²»±äµÄ RSC API °æ±¾
Expo ËùÓÐÔ̺¬ react-server-dom-webpack°æ±¾
Redwood SDK£ºrwsdk < 1.0.0-alpha.0
Waku ËùÓÐÔ̺¬ react-server-dom-webpack°æ±¾
@vitejs/plugin-rsc ËùÓÐʹÓò»°²È«°æ±¾µÄ²å¼þ


Èý¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


¹Ù·½ÒѰ䲼½¨¸´²¹¶¡£¬£¬£¬£¬£¬£¬ÒÔ½¨¸´¸Ã·ì϶¡£¡£¡£¡£¡£¡£¡£

React Server >= 19.0.3
React Server >= 19.1.4
React Server >= 19.2.3
Next.js
Éý¼¶µ½ÒÔϽ¨¸´°æ±¾£º
npm install next@15.0.5 £¨ºÏÓÃÓÚ 15.0.x£©
npm install next@15.1.9 £¨ºÏÓÃÓÚ 15.1.x£©
npm install next@15.2.6 £¨ºÏÓÃÓÚ 15.2.x£©
npm install next@15.3.6 £¨ºÏÓÃÓÚ 15.3.x£©
npm install next@15.4.8 £¨ºÏÓÃÓÚ 15.4.x£©
npm install next@15.5.7 £¨ºÏÓÃÓÚ 15.5.x£©
npm install next@16.0.7 £¨ºÏÓÃÓÚ 16.0.x£©
ÈôÊÇʹÓà Next.js 14.3.0-canary.77 »ò¸ü¸ß°æ±¾£¬£¬£¬£¬£¬£¬Çë½µ¼¶µ½×îеIJ»±ä 14.x °æ±¾£º
npm install next@14
React Router
ÈôÊÇʹÓà React Router µÄ²»²»±ä RSC API£¬£¬£¬£¬£¬£¬Éý¼¶ÒÔÏÂÒÀÀµ£º
npm install react@latest
npm install react-dom@latest
npm install react-server-dom-parcel@latest
npm install react-server-dom-webpack@latest
npm install @vitejs/plugin-rsc@latest
Expo
Éý¼¶ÖÁ×îа汾µÄ react-server-dom-webpack£º
npm install react@latest react-dom@latest react-server-dom-webpack@latest
Redwood SDK
È·±£°æ±¾Îª rwsdk >= 1.0.0-alpha.0
×îРbeta °æ±¾£º
npm install rwsdk@latest
Éý¼¶ÖÁ×îа汾µÄ react-server-dom-webpack£º
npm install react@latest react-dom@latest react-server-dom-webpack@latest
Waku
Éý¼¶ÖÁ×îа汾µÄ react-server-dom-webpack£º
npm install react@latest react-dom@latest react-server-dom-webpack@latest
@vitejs/plugin-rsc
Éý¼¶ÖÁ×îа汾µÄ RSC ²å¼þ£º
npm install react@latest react-dom@latest @vitejs/plugin-rsc@latest
react-server-dom-parcel
Éý¼¶ÖÁ×îа汾£º
npm install react@latest react-dom@latest react-server-dom-parcel@latest
react-server-dom-turbopack
Éý¼¶ÖÁ×îа汾£º
npm install react@latest react-dom@latest react-server-dom-turbopack@latest
react-server-dom-webpack
Éý¼¶ÖÁ×îа汾£º
npm install react@latest react-dom@latest react-server-dom-webpack@latest¡£¡£¡£¡£¡£¡£¡£


3.2 һʱ´ëÊ©


ÔÝÎÞ¡£¡£¡£¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬£¬Ï÷¼õϵͳ·ì϶£¬£¬£¬£¬£¬£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£¡£¡£¡£¡£¡£¡£
¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬£¬£¬£¬£¬£¬Åú¸Ä·À»ðǽսÊõ£¬£¬£¬£¬£¬£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬£¬£¬£¬£¬£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬£¬£¬£¬£¬£¬Ï÷¼õ¹¥»÷Ãæ¡£¡£¡£¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£¡£¡£¡£¡£¡£¡£
¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£¡£¡£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components/