Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/cybertechajju/cve-2025-55184-poc-expolit
Vulnerability ScannersPayload GenerationExploitationWeb Application ExploitationWAF BypassPenetration TestingLearning & EducationRed Teaming
GitHub
cybertechajju/cve-2025-55184-poc-expolit

CVE-2025-55184-POC-Expolit

Professional-grade Denial of Service (DoS) exploitation framework for CVE-2025-55184 targeting React Server Components. Features 8 attack modes, WAF bypass, and 10+ payload variants for authorized security testing and bug bounty hunting.

View Repository
22219 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🔥 CVE-2025-55184 Advanced Exploitation Tool

Security Python License Stars

Professional React Server Components DoS Exploitation Framework

"KEEP LEARNING KEEP HACKING" - CyberTechAjju

🚀 Quick Start • 📖 Documentation • 💻 Features • ⚠️ Disclaimer


🎯 About CVE-2025-55184

CVE-2025-55184 is a high-severity Denial of Service (DoS) vulnerability affecting React Server Components (RSC) implementations. The vulnerability allows remote attackers to cause complete service disruption through specially crafted circular reference payloads.

📊 Vulnerability Details

PropertyValue
CVE IDCVE-2025-55184
CVSS Score7.5 (High)
Attack VectorNetwork (Remote)
ComplexityLow
Privileges RequiredNone (Unauthenticated)
ImpactComplete DoS, Resource Exhaustion

🎯 Affected Frameworks

  • ❌ Next.js (versions 13.x - 14.1.0)
  • ❌ Waku (versions < 0.19.2)
  • ❌ Remix (versions < 2.5.1)
  • ❌ Any RSC-enabled React app (React 18.0.0 - 18.2.0)

✅ Patched Versions

  • ✅ Next.js ≥ 14.1.1
  • ✅ Waku ≥ 0.19.2
  • ✅ Remix ≥ 2.5.1
  • ✅ React ≥ 18.3.0

🔥 What Makes This Tool Special?

This isn't just a basic PoC - it's a professional-grade exploitation framework designed for serious security researchers and bug bounty hunters.

⚡ Unique Features

  • 🎯 Sustained Attack Mode - Keeps target down until you stop it (Ctrl+C for auto-recovery!)
  • 🛡️ Advanced WAF Bypass - Auto-detects and evades 8+ major WAFs (Cloudflare, AWS, Akamai, etc.)
  • 🎨 Beautiful Terminal UI - Cyberpunk-themed with live dashboards
  • 📊 Professional Reports - JSON/Markdown/HTML with CVSS scoring
  • 🔐 Ethical Safeguards - Built-in authorization checks and disclaimers
  • 💣 10+ Payload Variants - Base64, URL, Unicode, Hex encoding & more

🚀 Quick Start

Installation (One Command!)

root@kitploit:~
git clone https://github.com/CyberTechAjju/CVE-2025-55184-POC-Expolit.git
cd CVE-2025-55184-POC-Expolit
./run.sh

That's it! Dependencies auto-install, interactive menu guides you.

Alternative Methods

root@kitploit:~
# Python directly
python3 exploit.py

# Advanced CLI mode
python3 cve_2025_55184_exploit.py -t <target> -m scan

💻 Features

🎯 8 Attack Modes

ModeDescriptionUse Case
1. DetectPassive fingerprintingSafe reconnaissance
2. ScanActive vulnerability testingConfirmation
3. SingleOne-shot PoCQuick demo
4. MultiMulti-threaded (5 threads)Moderate testing
5. AggressiveHigh-impact (10+ threads)Authorized pentest
6. WAFWAF detection & bypassProtected targets
7. ReportGenerate documentationBug bounty submission
8. Sustained🔥 NEW! Continuous DoSKeeps target down!

💥 Sustained Attack Mode (Killer Feature!)

root@kitploit:~
./run.sh
# Choose: 3 (SUSTAINED ATTACK)
# ✅ Target goes DOWN and STAYS DOWN
# ✅ Press Ctrl+C → Target RECOVERS automatically

Perfect for:

  • Testing DoS resilience
  • Demonstrating impact to clients
  • Bug bounty proof-of-concept
  • Authorized penetration testing

🛡️ WAF Bypass Capabilities

Auto-detected WAFs:

  • Cloudflare
  • AWS WAF
  • Akamai
  • Imperva
  • F5 BIG-IP
  • Sucuri
  • ModSecurity
  • Wordfence

Evasion Techniques:

  • Multiple encoding (Base64, URL, Unicode, Hex)
  • Header obfuscation & randomization
  • User-Agent rotation (6+ profiles)
  • HTTP request smuggling
  • Null byte injection
  • Double encoding chains
  • Timing variation
  • Proxy header spoofing

📖 Documentation

  • docs/QUICKSTART.md - ⚡ Quick start guide (READ THIS FIRST!)
  • docs/USAGE.md - Comprehensive usage guide
  • docs/BUG_BOUNTY_EMAIL_TEMPLATE.md - Professional email report format
  • config/config.json - Configuration reference
  • config/payloads.json - Payload database

🎥 Related Resources

📹 CVE-2025-55182 Exploit Tutorial

Looking for CVE-2025-55182 exploitation? Check out this video:

CVE-2025-55182 Tutorial

▶️ Watch on YouTube: CVE-2025-55182 Exploitation


🎨 Screenshots

Terminal Banner

root@kitploit:~
╔══════════════════════════════════════════════════════════╗
║                                                          ║
║     ______     ________    _____    ___   ___            ║
║    / ____/    / ____/ /   / __  \  / _ \ / _ \           ║
║   / /   __   / /_  / /    \__ \ / / /_\ / /_\ \          ║
║  / /__ /  \ /___/ / /___ ___/ /_/\__  /\__  /           ║
║  \____/    /_____/______//____/     /_/   /_/            ║
║                                                          ║
║   by CyberTechAjju | "KEEP LEARNING KEEP HACKING"       ║
╚══════════════════════════════════════════════════════════╝

Live Attack Dashboard

root@kitploit:~
⚡ LIVE ATTACK DASHBOARD ⚡
┌─────────────────────────────────────────────────┐
│ Total Requests        │    847    │     ✓       │
│ Successful Attacks    │    521    │     💥      │
│ Timeouts              │    521    │     ⏱️      │
│ Errors                │    326    │     ❌      │
│ Success Rate          │   61.5%   │     🎯      │
└─────────────────────────────────────────────────┘

💡 Usage Examples

Example 1: Quick Vulnerability Check

root@kitploit:~
./run.sh
Enter target: http://localhost:3000
Choose: 1 (Quick Scan)
Authorization: YES I AM AUTHORIZED
# Results in seconds!

Example 2: Sustained DoS Attack

root@kitploit:~
./run.sh
Enter target: http://vulnerable-site.com
Choose: 3 (SUSTAINED ATTACK)
Authorization: YES I AM AUTHORIZED
Type: ATTACK
# Target goes down
# Monitor impact
# Press Ctrl+C when done
# Target recovers automatically!

Example 3: WAF-Protected Target

root@kitploit:~
./run.sh
Enter target: https://protected.cloudflare.com
Choose: 4 (WAF Bypass)
# Auto-detects Cloudflare
# Tries encoding variations
# Shows bypass success/failure

📊 Payload Arsenal

This tool includes 10+ exploit variations:

Payload TypeEncodingSuccess RateDescription
BasicNone95%Original circular reference
URL EncodedURL80%Bypass simple filters
Base64Base6475%Evade pattern matching
Double URL2x URL70%Advanced WAF bypass
UnicodeUnicode65%Character encoding evasion
HexHexadecimal60%Hex escape sequences
MixedVarious55%Combined techniques
FragmentedSplit50%Fragment-based bypass
NestedNone85%Deeper recursion
Array-basedNone70%Array circular refs

🔐 Ethical Safeguards

Built-in Protection Mechanisms

✅ Authorization Prompts - Must type "YES I AM AUTHORIZED" before every attack
✅ Legal Warnings - Displayed on startup with clear guidelines
✅ Graceful Shutdown - Ctrl+C stops cleanly, allows target recovery
✅ Rate Limiting - Configurable delays prevent unintended damage
✅ Scope Validation - Authorized domains list in config
✅ Comprehensive Logging - All actions logged for accountability


⚠️ Legal Disclaimer

root@kitploit:~
🚨 AUTHORIZED USE ONLY 🚨

This tool is designed EXCLUSIVELY for:
  ✅ Authorized penetration testing with written permission
  ✅ Bug bounty programs within defined scope
  ✅ Security research in controlled environments
  ✅ Educational purposes on your own infrastructure

UNAUTHORIZED USE IS STRICTLY PROHIBITED AND ILLEGAL!

The author (CyberTechAjju) assumes NO responsibility for:
  ❌ Misuse of this tool
  ❌ Unauthorized testing or attacks
  ❌ Damage to systems or services
  ❌ Legal consequences from improper use

By using this tool, you agree to:
  ✓ Obtain explicit written authorization before testing
  ✓ Comply with all applicable laws and regulations
  ✓ Follow responsible disclosure practices
  ✓ Use only for legitimate security research

🏆 Bug Bounty Workflow

Perfect for professional bug bounty hunting:

root@kitploit:~
graph LR
    A[Recon] --> B[Detect Mode]
    B --> C[Scan Mode]
    C --> D[Confirm Vuln]
    D --> E[Generate Report]
    E --> F[Submit]
    F --> G[Reward! 💰]
  1. Reconnaissance - Use detect mode (passive)
  2. Verification - Run scan mode (active)
  3. PoC Development - Single or sustained attack
  4. Documentation - Generate professional report
  5. Submission - Use email template provided
  6. Collaboration - Work with security team
  7. Disclosure - Responsible disclosure after patch

📁 Project Structure

root@kitploit:~
CVE-2025-55184-POC-Expolit/
├── run.sh                           # 🚀 Quick launcher (START HERE!)
├── exploit.py                       # 🎯 Simple interactive mode
├── cve_2025_55184_exploit.py       # 🔧 Advanced CLI tool
├── requirements.txt                 # 📦 Dependencies
├── README.md                        # 📄 This file
├── .gitignore                       # Ignore patterns
│
├── modules/                         # 🔌 Core modules
│   ├── ui_manager.py               # 🎨 Terminal UI engine
│   ├── waf_bypass.py               # 🛡️ WAF evasion module
│   └── utils.py                    # 🔧 Utilities & reporting
│
├── config/                          # ⚙️ Configuration files
│   ├── config.json                 # Settings & attack modes
│   └── payloads.json               # 💣 Exploit database (10+ variants)
│
└── docs/                            # 📚 Documentation
    ├── QUICKSTART.md               # ⚡ Quick start guide
    ├── USAGE.md                    # 📖 Detailed documentation
    └── BUG_BOUNTY_EMAIL_TEMPLATE.md # 📧 Email report format

🛠️ Technical Details

How It Works

  1. Payload Crafting - Generates circular reference ("$@0")
  2. Header Injection - Adds Next-Action: x or framework-specific headers
  3. Request Sending - POSTs malformed data to RSC endpoint
  4. Server Processing - RSC deserializer encounters self-reference
  5. Infinite Loop - Server enters infinite recursion
  6. Resource Exhaustion - CPU/Memory spike to 100%
  7. Service Disruption - Application becomes unresponsive
  8. DoS Achievement - Complete denial of service

Root Cause

root@kitploit:~
// Vulnerable RSC deserialization logic
function deserialize(payload) {
  if (payload.startsWith("$@")) {
    const ref = parseInt(payload.substring(2));
    return deserialize(payload); // ← Infinite recursion!
  }
}

🤝 Contributing

Contributions welcome! Areas for improvement:

  • Additional framework support
  • New WAF bypass techniques
  • Payload variations
  • Documentation enhancements
  • Bug fixes

Note: All contributions must maintain ethical use principles.


📚 References

  • CVE-2025-55184 - NVD
  • Next.js Security Advisories
  • React Server Components
  • OWASP Testing Guide
  • CVE-2025-55182 Tutorial

📧 Contact & Support

Author: CyberTechAjju
Motto: "KEEP LEARNING KEEP HACKING"

Found a bug? Have suggestions? Open an issue!


📄 License

Authorized Use Only - This tool is provided for legitimate security testing purposes only. Unauthorized use is prohibited by law.


🌟 Show Your Support

If this tool helped you in bug bounty or security research:

  • ⭐ Star this repository
  • 🐛 Report bugs via issues
  • 📧 Share your success stories
  • 🔄 Contribute improvements

🔥 Made with ⚡ by CyberTechAjju

"KEEP LEARNING KEEP HACKING"

Empowering ethical hackers to make the web more secure, one vulnerability at a time.


Visitors GitHub issues GitHub forks GitHub stars

Download Tool