On this page
Atomicorp WAF Rule 345250
Rule Summary
- Rule ID: 345250
- Status: Active
- Alert message: Atomicorp.com WAF Rules: CVE-2025-55183 React RSC source disclosure probe (DETECT)
- Observed CWEs: None documented
- Revision: 2
- Rule severity: Warning
- Phase: 2 (request body)
- Rule action: pass
- Public tags: attack-disclosure, no_ar
- Logging: log, auditlog
Description
This rule detects behavior identified by its current alert as “CVE-2025-55183 React RSC source disclosure probe (DETECT)”. It evaluates during the request body phase and records the match without a disruptive action.
CVEs Referenced by This Rule
The current ModSecurity rule metadata explicitly names the following CVEs. These references explain the rule author’s association; they do not claim that the rule is limited to these vulnerabilities or that this is an exhaustive coverage list.
CVE-2025-55183
An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. A specifically crafted HTTP request sent to a vulnerable Server Function may unsafely return the source code of any Server Function. Exploitation requires the existence of a Server Function which explicitly or implicitly exposes a stringified argument.
- Association: The rule references CVE-2025-55183 in its alert message.
- CVE Record (opens in a new tab)
- NVD (opens in a new tab)
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
No selected related public CVE research notes are currently published.