React: CVE-2025-55184, CVE-2025-67779 & CVE-2025-55183 - Denial of Service and Source Code Exposure in React Server Components #500

Closed
opened 2026-04-05 17:13:09 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @jaydrogers on 12/12/2025

Describe the Bug

I appreciate the team quickly addressing:

Similar news hit the React world yesterday with a new set of CVEs:

One of them is a source code exposure (which I understand isn't a vulnerability in an open source project 😃), but I'm mainly more concerned about the Denial Of Service attack.

What I'm looking for

Is it possible for the Pangolin team to take a look at this and let us know if these CVEs affect the Pangolin project?

I'm not a React expert so some of these component terms are foreign to me 😅

Thanks for all your work on this incredible project!

*Originally created by @jaydrogers on 12/12/2025* ### Describe the Bug I appreciate the team quickly addressing: - https://github.com/fosrl/pangolin/issues/2031 Similar news hit the React world yesterday with a new set of CVEs: - https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components One of them is a source code exposure (which I understand isn't a vulnerability in an open source project 😃), but I'm mainly more concerned about the Denial Of Service attack. ### What I'm looking for Is it possible for the Pangolin team to take a look at this and let us know if these CVEs affect the Pangolin project? I'm not a React expert so some of these component terms are foreign to me 😅 Thanks for all your work on this incredible project!
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/pangolin#500