On this page

Atomicorp WAF Rule 345250

Rule Summary

  • Rule ID: 345250
  • Status: Active
  • Alert message: Atomicorp.com WAF Rules: CVE-2025-55183 React RSC source disclosure probe (DETECT)
  • Observed CWEs: None documented
  • Revision: 2
  • Rule severity: Warning
  • Phase: 2 (request body)
  • Rule action: pass
  • Public tags: attack-disclosure, no_ar
  • Logging: log, auditlog

Description

This rule detects behavior identified by its current alert as “CVE-2025-55183 React RSC source disclosure probe (DETECT)”. It evaluates during the request body phase and records the match without a disruptive action.

CVEs Referenced by This Rule

The current ModSecurity rule metadata explicitly names the following CVEs. These references explain the rule author’s association; they do not claim that the rule is limited to these vulnerabilities or that this is an exhaustive coverage list.

CVE-2025-55183

An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. A specifically crafted HTTP request sent to a vulnerable Server Function may unsafely return the source code of any Server Function. Exploitation requires the existence of a Server Function which explicitly or implicitly exposes a stringified argument.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

No selected related public CVE research notes are currently published.