logo

AL25-018 - Vulnerability affecting React Server Components - CVE-2025-55182

ID: 1e0c52d0-836b-5330-9ffa-07a37b354ab0

STIX ID: report--1e0c52d0-836b-5330-9ffa-07a37b354ab0

Feed Name: Canadian Centre for Cyber Security Alerts and Advisories

Threat Score
85/100

Date Published: 2025-12-04

Date Updated: 2026-06-11

Author: Canadian Centre for Cyber Security

...
...

The Canadian Centre for Cyber Security warns of a critical pre-authentication RCE (CVE-2025-55182) in the React Server Components (RSC) Flight protocol impacting React 19 and many frameworks (notably Next.js); public PoCs and easy exploitation have been reported. The alert lists affected packages and fixed versions, recommends immediate patching or mitigations (WAF, access restrictions, disabling RSC), and urges organizations to follow vendor guidance and Cyber Centre security actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.