logo

Critical React Server Components RCE (CVE-2025-55182): What You Need to Patch Now

ID: cc75c046-2ab7-51bb-b252-43995b4ce0e7

STIX ID: report--cc75c046-2ab7-51bb-b252-43995b4ce0e7

Feed Name: Abstract Security Blog

Threat Score
90/100

Date Published: 2025-12-03

Date Updated: 2026-04-26

...
...

CVE-2025-55182 is a critical (CVSS 10.0) unauthenticated remote code execution vulnerability in React Server Components (react-server) and affected frameworks including Next.js; it stems from insecure deserialization of RSC "Flight" protocol payloads and is exploitable in default configurations. The advisory lists vulnerable and patched versions, exploitation indicators (e.g., POSTs to server function endpoints containing __proto__/constructor/prototype keys), detection queries, and immediate remediation guidance to upgrade to specified patched releases and implement monitoring and incident response measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.