Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | React Server Components »Ø¾ø·þÎñ·ì϶ |
CVE ID | CVE-2025-55184 |
·ì϶ÀàÐÍ | DOS | ·¢ÏÖ¹¦·ò | 2025-12-12 |
·ì϶ÆÀ·Ö | 7.5 | ·ì϶µÈ¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
ReactÊÇÒ»¸öÓÃÓÚ¹¹½¨Óû§½çÃæµÄJavaScript¿â£¬ÓÉFacebook¿ª·¢ºÍÊØ»¤¡£Ëü»ùÓÚ×é¼þ»¯µÄ¿ª·¢Ä£Ê½£¬Í¨¹ýÉêÃ÷ʽ±à³Ì¼ò»¯Á˽çÃæµÄ¹¹½¨ºÍ¸üС£Reactͨ¹ýÐé¹¹DOMÌáÉýäÖȾ»úÄÜ£¬È·±£×îÓ×»¯¶ÔÕæÊµDOMµÄ²Ù×÷£¬ÓÅ»¯ÁËÀûÓõÄÏìÓ¦¿ìÂÊ¡£ËüÖ§³Öµ¥ÏòÊý¾ÝÁ÷£¬ÌáÉýÁËÀûÓõĿÉÔ¤²âÐԺͿÉÊØ»¤ÐÔ¡£React¿ÉÓëÆäËû¿â»ò¿ò¼Üһ·ʹÓ㬳£¼ûµÄ×éºÏÔ̺¬React RouterÓÃÓÚ·ÓÉÖÎÀíºÍReduxÓÃÓÚ״̬ÖÎÀí¡£ReactºÏÓÃÓÚ¹¹½¨ÏÖ´úWebºÍÒÆ¶¯¶ËÀûÓã¬¿í·ºÀûÓÃÓÚǰ¶Ë¿ª·¢ÁìÓò¡£
2025Äê12ÔÂ12ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½React Server Components´æÔÚ¶à¸ö°²È«·ì϶£¬Ô̺¬React Server Components »Ø¾ø·þÎñ·ì϶(CVE-2025-55184)¡¢React Server Components »Ø¾ø·þÎñ·ì϶(CVE-2025-67779)¡¢React Server Components Ô´´úÂë¶¶Âí½Å(CVE-2025-55183)£¬ÆäÖÐCVE-2025-55184ÊÇÒ»¸ö¸ßΣ»Ø¾ø·þÎñ£¨DoS£©·ì϶£¬¹¥»÷ÕßÄܹ»Í¨¹ý¶ñÒâ»ú¹ØµÄHTTPÒªÇ󣬷¢ËÍÖÁReact Server Function¶Ëµã£¬µ¼Ö·´ÐòÁл¯¹ý³ÌÖеÄÎÞÏÞÑ»·£¬´Ó¶ø¿÷Ëð´óÁ¿CPU×ÊÔ´£¬Ôì³É·þÎñ²»³ÉÓá£CVE-2025-67779ÓëCVE-2025-55184Óйأ¬¹¥»÷ÕßÄܹ»ÀûÓöñÒâHTTPÒªÇó´¥·¢ÎÞÏÞÑ»·£¬µ¼Ö·þÎñÆ÷×ÊÔ´¿÷Ëð´ù¾¡²¢Ê¹·þÎñÖжϡ£CVE-2025-55183ÊÇÒ»¸öÖÐΣԴ´úÂë¶¶Âí½Å£¬¹¥»÷Õßͨ¹ý¶ñÒâHTTPÒªÇó¿ÉÄܵ¼ÖÂReact Server ComponentsÖеķþÎñÆ÷¶Ëº¯Êýй¶Դ´úÂ룬¶³öÃô¸ÐÊý¾Ý£¬ÈçÓ²±àÂëµÄÊý¾Ý¿âÏνÓÐÅÏ¢¡£
¶þ¡¢Ó°ÏìÁìÓò
react-server-dom-webpack¡¢react-server-dom-parcel¡¢react-server-dom-turbopack = 19.0.0¡¢19.0.1¡¢19.0.2
react-server-dom-webpack¡¢react-server-dom-parcel¡¢react-server-dom-turbopack = 19.1.0¡¢19.1.1¡¢19.1.2¡¢19.1.2react-server-dom-webpack¡¢react-server-dom-parcel¡¢react-server-dom-turbopack = 19.2.0¡¢19.2.1¡¢19.2.2React Router ²»²»±äµÄ RSC API °æ±¾Expo ËùÓÐÔ̺¬ react-server-dom-webpack°æ±¾Redwood SDK£ºrwsdk < 1.0.0-alpha.0Waku ËùÓÐÔ̺¬ react-server-dom-webpack°æ±¾@vitejs/plugin-rsc ËùÓÐʹÓò»°²È«°æ±¾µÄ²å¼þ
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
¹Ù·½ÒѰ䲼½¨¸´²¹¶¡£¬ÒÔ½¨¸´¸Ã·ì϶¡£
npm install next@15.0.5 £¨ºÏÓÃÓÚ 15.0.x£©npm install next@15.1.9 £¨ºÏÓÃÓÚ 15.1.x£©npm install next@15.2.6 £¨ºÏÓÃÓÚ 15.2.x£©npm install next@15.3.6 £¨ºÏÓÃÓÚ 15.3.x£©npm install next@15.4.8 £¨ºÏÓÃÓÚ 15.4.x£©npm install next@15.5.7 £¨ºÏÓÃÓÚ 15.5.x£©npm install next@16.0.7 £¨ºÏÓÃÓÚ 16.0.x£©ÈôÊÇʹÓà Next.js 14.3.0-canary.77 »ò¸ü¸ß°æ±¾£¬Çë½µ¼¶µ½×îеIJ»±ä 14.x °æ±¾£ºÈôÊÇʹÓà React Router µÄ²»²»±ä RSC API£¬Éý¼¶ÒÔÏÂÒÀÀµ£ºnpm install react-dom@latestnpm install react-server-dom-parcel@latestnpm install react-server-dom-webpack@latestnpm install @vitejs/plugin-rsc@latestÉý¼¶ÖÁ×îа汾µÄ react-server-dom-webpack£ºnpm install react@latest react-dom@latest react-server-dom-webpack@latestÈ·±£°æ±¾Îª rwsdk >= 1.0.0-alpha.0Éý¼¶ÖÁ×îа汾µÄ react-server-dom-webpack£ºnpm install react@latest react-dom@latest react-server-dom-webpack@latestÉý¼¶ÖÁ×îа汾µÄ react-server-dom-webpack£ºnpm install react@latest react-dom@latest react-server-dom-webpack@latestÉý¼¶ÖÁ×îа汾µÄ RSC ²å¼þ£ºnpm install react@latest react-dom@latest @vitejs/plugin-rsc@latestnpm install react@latest react-dom@latest react-server-dom-parcel@latestreact-server-dom-turbopacknpm install react@latest react-dom@latest react-server-dom-turbopack@latestnpm install react@latest react-dom@latest react-server-dom-webpack@latest¡£
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£
3.3 ͨÓý¨Òé
? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£? ¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£? ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£? ¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£? ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£
3.4 ²Î¿¼Á´½Ó
https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components/