WPE
Beta
¡Usuario con pocos negocios! ¡Utiliza siempre saldo de Forobeta!
Hola, aquí Guille de WPE, el otro día ya lo comentó nuestro CTO Oscar:
https://forobeta.com/temas/causa-fr...en-soporte-para-laravel.1075367/#post-9984440
pero hoy Vercel reportó 2 nuevas vulnerabilidades más, aqui copio parte del email que recibimos:
Son vulnerabilidades críticas y si tienes apps alojadas en Vercel o programadas con Nextjs tienes que seguir las instrucciones para instalarte las actualizaciones.
Si necesitan ayuda profesional, pueden contactarnos:
https://wpe.net.pe
Telegram/Whatsapp: +51 970 196 659
https://forobeta.com/temas/causa-fr...en-soporte-para-laravel.1075367/#post-9984440
pero hoy Vercel reportó 2 nuevas vulnerabilidades más, aqui copio parte del email que recibimos:
[td][/td]
We're informing you about two additional vulnerabilities (CVE-2025-55184 and CVE-2025-55183) identified in the React Server Components (RSC) implementation, affecting frameworks such as Next.js.
[td][/td]
The React2Shell incident sparked community research into React Server Components, and these vulnerabilities were discovered by an external security researcher through Vercel and Meta's bug bounty program. We're grateful for this community effort.
[td][/td]
There is no evidence these vulnerabilities have been exploited.
[td][/td]
What we've found:
- CVE-2025-55184 (High Severity – Denial of Service): A malicious HTTP request sent to any App Router endpoint can, when deserialized, cause the server process to hang and consume CPU. This impacts all versions handling RSC requests. The initial fix was incomplete and did not fully prevent denial-of-service attacks for all payload types, resulting in CVE-2025-67779.
- CVE-2025-55183 (Medium Severity – Source Code Exposure): A malicious HTTP request sent to any App Router endpoint can return the compiled source code of Server Actions. This could reveal business logic, but would not expose secrets unless they were hardcoded directly into a Server Action's code.
Son vulnerabilidades críticas y si tienes apps alojadas en Vercel o programadas con Nextjs tienes que seguir las instrucciones para instalarte las actualizaciones.
Si necesitan ayuda profesional, pueden contactarnos:
https://wpe.net.pe
Telegram/Whatsapp: +51 970 196 659

