AL25-018 - Vulnerability affecting React Server Components - CVE-2025-55182
ID: 1e0c52d0-836b-5330-9ffa-07a37b354ab0
STIX ID: report--1e0c52d0-836b-5330-9ffa-07a37b354ab0
Feed Name: Canadian Centre for Cyber Security Alerts and Advisories
The Canadian Centre for Cyber Security warns of a critical pre-authentication RCE (CVE-2025-55182) in the React Server Components (RSC) Flight protocol impacting React 19 and many frameworks (notably Next.js); public PoCs and easy exploitation have been reported. The alert lists affected packages and fixed versions, recommends immediate patching or mitigations (WAF, access restrictions, disabling RSC), and urges organizations to follow vendor guidance and Cyber Centre security actions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
