¡¾Îó²îͨ¸æ¡¿React Server Components ¾Ü¾øÐ§ÀÍÎó²î(CVE-2025-55184)

Ðû²¼Ê±¼ä 2025-12-12

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

React Server Components ¾Ü¾øÐ§ÀÍÎó²î

CVE   ID

CVE-2025-55184

Îó²îÀàÐÍ

DOS

·¢Ã÷ʱ¼ä

2025-12-12

Îó²îÆÀ·Ö

7.5

Îó²îÆ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

²»ÐèÒª

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


ReactÊÇÒ»¸öÓÃÓÚ¹¹½¨Óû§½çÃæµÄJavaScript¿â £¬£¬£¬£¬£¬ÓÉFacebook¿ª·¢ºÍά»¤ ¡£¡£¡£¡£¡£¡£Ëü»ùÓÚ×é¼þ»¯µÄ¿ª·¢Ä£Ê½ £¬£¬£¬£¬£¬Í¨¹ýÉùÃ÷ʽ±à³Ì¼ò»¯Á˽çÃæµÄ¹¹½¨ºÍ¸üР¡£¡£¡£¡£¡£¡£Reactͨ¹ýÐéÄâDOMÌáÉýäÖȾÐÔÄÜ £¬£¬£¬£¬£¬È·±£×îС»¯¶ÔÕæÊµDOMµÄ²Ù×÷ £¬£¬£¬£¬£¬ÓÅ»¯ÁËÓ¦ÓõÄÏìÓ¦ËÙÂÊ ¡£¡£¡£¡£¡£¡£ËüÖ§³Öµ¥ÏòÊý¾ÝÁ÷ £¬£¬£¬£¬£¬ÌáÉýÁËÓ¦ÓõĿÉÕ¹ÍûÐԺͿÉά»¤ÐÔ ¡£¡£¡£¡£¡£¡£React¿ÉÓëÆäËû¿â»ò¿ò¼ÜÒ»ÆðʹÓà £¬£¬£¬£¬£¬³£¼ûµÄ×éºÏ°üÀ¨React RouterÓÃÓÚ·ÓÉÖÎÀíºÍReduxÓÃÓÚ״̬ÖÎÀí ¡£¡£¡£¡£¡£¡£ReactÊÊÓÃÓÚ¹¹½¨ÏÖ´úWebºÍÒÆ¶¯¶ËÓ¦Óà £¬£¬£¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚǰ¶Ë¿ª·¢ÁìÓò ¡£¡£¡£¡£¡£¡£


2025Äê12ÔÂ12ÈÕ £¬£¬£¬£¬£¬c7c7ÓéÀÖÆ½Ì¨¼¯ÍÅVSRC¼à²âµ½React Server Components±£´æ¶à¸öÇå¾²Îó²î £¬£¬£¬£¬£¬°üÀ¨React Server Components ¾Ü¾øÐ§ÀÍÎó²î(CVE-2025-55184)¡¢React Server Components ¾Ü¾øÐ§ÀÍÎó²î(CVE-2025-67779)¡¢React Server Components Ô´´úÂë̻¶Îó²î(CVE-2025-55183) £¬£¬£¬£¬£¬ÆäÖÐCVE-2025-55184ÊÇÒ»¸ö¸ßΣ¾Ü¾øÐ§ÀÍ£¨DoS£©Îó²î £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý¶ñÒâ½á¹¹µÄHTTPÇëÇó £¬£¬£¬£¬£¬·¢ËÍÖÁReact Server Function¶Ëµã £¬£¬£¬£¬£¬µ¼Ö·´ÐòÁл¯Àú³ÌÖеÄÎÞÏÞÑ­»· £¬£¬£¬£¬£¬´Ó¶øÏûºÄ´ó×ÚCPU×ÊÔ´ £¬£¬£¬£¬£¬Ôì³ÉЧÀͲ»¿ÉÓà ¡£¡£¡£¡£¡£¡£CVE-2025-67779ÓëCVE-2025-55184Ïà¹Ø £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓöñÒâHTTPÇëÇó´¥·¢ÎÞÏÞÑ­»· £¬£¬£¬£¬£¬µ¼ÖÂЧÀÍÆ÷×ÊÔ´ÏûºÄ´ù¾¡²¢Ê¹Ð§ÀÍÖÐÖ¹ ¡£¡£¡£¡£¡£¡£CVE-2025-55183ÊÇÒ»ÆäÖÐΣԴ´úÂë̻¶Îó²î £¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ý¶ñÒâHTTPÇëÇó¿ÉÄܵ¼ÖÂReact Server ComponentsÖеÄЧÀÍÆ÷¶Ëº¯Êýй¶Դ´úÂë £¬£¬£¬£¬£¬Ì»Â¶Ãô¸ÐÊý¾Ý £¬£¬£¬£¬£¬ÈçÓ²±àÂëµÄÊý¾Ý¿âÅþÁ¬ÐÅÏ¢ ¡£¡£¡£¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


react-server-dom-webpack¡¢react-server-dom-parcel¡¢react-server-dom-turbopack = 19.0.0¡¢19.0.1¡¢19.0.2

react-server-dom-webpack¡¢react-server-dom-parcel¡¢react-server-dom-turbopack = 19.1.0¡¢19.1.1¡¢19.1.2¡¢19.1.2
react-server-dom-webpack¡¢react-server-dom-parcel¡¢react-server-dom-turbopack = 19.2.0¡¢19.2.1¡¢19.2.2
ÆäËûÊÜÓ°Ïì¿ò¼ÜºÍ´ò°ü³ÌÐò
Next.js <= 15.0.0
React Router ²»ÎÈ¹ÌµÄ RSC API °æ±¾
Expo ËùÓаüÀ¨ react-server-dom-webpack°æ±¾
Redwood SDK£ºrwsdk < 1.0.0-alpha.0
Waku ËùÓаüÀ¨ react-server-dom-webpack°æ±¾
@vitejs/plugin-rsc ËùÓÐʹÓò»Çå¾²°æ±¾µÄ²å¼þ


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡ £¬£¬£¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î ¡£¡£¡£¡£¡£¡£

React Server >= 19.0.3
React Server >= 19.1.4
React Server >= 19.2.3
Next.js
Éý¼¶µ½ÒÔÏÂÐÞ¸´°æ±¾£º
npm install next@15.0.5 £¨ÊÊÓÃÓÚ 15.0.x£©
npm install next@15.1.9 £¨ÊÊÓÃÓÚ 15.1.x£©
npm install next@15.2.6 £¨ÊÊÓÃÓÚ 15.2.x£©
npm install next@15.3.6 £¨ÊÊÓÃÓÚ 15.3.x£©
npm install next@15.4.8 £¨ÊÊÓÃÓÚ 15.4.x£©
npm install next@15.5.7 £¨ÊÊÓÃÓÚ 15.5.x£©
npm install next@16.0.7 £¨ÊÊÓÃÓÚ 16.0.x£©
ÈôÊÇʹÓà Next.js 14.3.0-canary.77 »ò¸ü¸ß°æ±¾ £¬£¬£¬£¬£¬Çë½µ¼¶µ½×îеÄÎÈ¹Ì 14.x °æ±¾£º
npm install next@14
React Router
ÈôÊÇʹÓà React Router µÄ²»ÎÈ¹Ì RSC API £¬£¬£¬£¬£¬Éý¼¶ÒÔÏÂÒÀÀµ£º
npm install react@latest
npm install react-dom@latest
npm install react-server-dom-parcel@latest
npm install react-server-dom-webpack@latest
npm install @vitejs/plugin-rsc@latest
Expo
Éý¼¶ÖÁ×îа汾µÄ react-server-dom-webpack£º
npm install react@latest react-dom@latest react-server-dom-webpack@latest
Redwood SDK
È·±£°æ±¾Îª rwsdk >= 1.0.0-alpha.0
×îРbeta °æ±¾£º
npm install rwsdk@latest
Éý¼¶ÖÁ×îа汾µÄ react-server-dom-webpack£º
npm install react@latest react-dom@latest react-server-dom-webpack@latest
Waku
Éý¼¶ÖÁ×îа汾µÄ react-server-dom-webpack£º
npm install react@latest react-dom@latest react-server-dom-webpack@latest
@vitejs/plugin-rsc
Éý¼¶ÖÁ×îа汾µÄ RSC ²å¼þ£º
npm install react@latest react-dom@latest @vitejs/plugin-rsc@latest
react-server-dom-parcel
Éý¼¶ÖÁ×îа汾£º
npm install react@latest react-dom@latest react-server-dom-parcel@latest
react-server-dom-turbopack
Éý¼¶ÖÁ×îа汾£º
npm install react@latest react-dom@latest react-server-dom-turbopack@latest
react-server-dom-webpack
Éý¼¶ÖÁ×îа汾£º
npm install react@latest react-dom@latest react-server-dom-webpack@latest ¡£¡£¡£¡£¡£¡£


3.2 ÔÝʱ²½·¥


ÔÝÎÞ ¡£¡£¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡ £¬£¬£¬£¬£¬ïÔ̭ϵͳÎó²î £¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ ¡£¡£¡£¡£¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ £¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ £¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ £¬£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø £¬£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ ¡£¡£¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ· £¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ ¡£¡£¡£¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí £¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò £¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È ¡£¡£¡£¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐÞ¸Ä ¡£¡£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components/